Junglewise Threat Intelligence

CVE-2026-83355: Oracle Enterprise Manager for Fusion Middleware remote code execution in Metrics

CVE-2026-83355 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Enterprise Manager for Fusion Middleware is a centralized management platform for Oracle Fusion applications and middleware infrastructure. An unauthenticated attacker can remotely exploit a vulnerability in the Metrics component to gain complete control of the system, potentially leading to unauthorized access to sensitive data, system compromise, and operational disruption across managed Fusion environments.

Technical details

This is an easily exploitable vulnerability in the Metrics component of Oracle Enterprise Manager for Fusion Middleware that requires no authentication. The flaw is remotely reachable via HTTP and allows an unauthenticated attacker on the network to achieve complete system compromise. The vulnerability results in high impact across confidentiality, integrity, and availability—meaning attackers can read sensitive data, modify configurations, and disrupt service. Patches are expected from Oracle for affected versions 13.5 and 24.1.

Affected products

  • Oracle Enterprise Manager for Fusion Middleware 13.5, 24.1

Timeline

  • 2026-09-15: disclosed

References