Junglewise Threat Intelligence

CVE-2026-83068: Oracle Enterprise Manager for Oracle Database authorization bypass in Core

CVE-2026-83068 · Severity: high · CVSS 7.7 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Enterprise Manager is a management platform used to monitor and administer Oracle databases across enterprises. A flaw in version 24.1 allows a low-privileged attacker with network access to bypass authorization controls and gain unauthorized access to sensitive database data. The vulnerability has a scope change—successful exploitation could compromise additional connected products beyond Enterprise Manager itself.

Technical details

This vulnerability in Oracle Enterprise Manager for Oracle Database (Core component, version 24.1) is an authorization bypass issue exploitable over the network via HTTP by a low-privileged authenticated user. The attack requires no user interaction and does not require elevated privileges; an attacker with basic network access and valid (low-privilege) credentials can trigger it. Successful exploitation results in unauthorized access to confidential data within Enterprise Manager and potentially impacts other Oracle products due to scope change. The vulnerability has not been publicly exploited in the wild as of the publication date, and patch availability should be verified through Oracle's security alerts.

Affected products

  • Oracle Enterprise Manager for Oracle Database 24.1

Timeline

  • 2026-09-15: disclosed

References