Junglewise Threat Intelligence

CVE-2026-70737: Oracle Enterprise Manager for Systems Infrastructure privilege escalation in Storage Server Management

CVE-2026-70737 · Severity: high · CVSS 8.8 · Published 2026-08-18

Vendors: Oracle.

Executive brief

Oracle Enterprise Manager for Systems Infrastructure is a suite for managing enterprise infrastructure and storage. A low-privileged attacker with network access can exploit a vulnerability in the Storage Server Management component to gain complete control over the system, compromising confidentiality, integrity, and availability of the management infrastructure and any systems it controls.

Technical details

The vulnerability is an easily exploitable flaw in the Storage Server Management component of Oracle Enterprise Manager for Systems Infrastructure. It requires only low-level privileges and network access via HTTP to trigger—no complex exploitation or user interaction needed. A successful attack grants full compromise of the affected system, including unauthorized access to sensitive data and the ability to modify or disable critical storage management functions. The vulnerability affects versions 13.5 and 24.1; patches from Oracle should be consulted for remediation.

Affected products

  • Oracle Enterprise Manager for Systems Infrastructure 13.5, 24.1

Timeline

  • 2026-08-18: disclosed

References