Vulnerability in Oracle Enterprise Manager Base Platform UI Framework
CVE-2026-46989

9.1CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-46989?

An exploitable flaw exists in the UI Framework of Oracle Enterprise Manager Base Platform, allowing an attacker with low privileges and network access via HTTPS to gain unauthorized entry. Successful exploitation could lead to unauthorized access to sensitive data, potential alterations or deletions of accessible data, and may even result in partial denial of service conditions for the affected Oracle Enterprise Manager products. Notably, attacks may also affect additional related products, amplifying the risk associated with this vulnerability.

Affected Version(s)

Oracle Enterprise Manager Base Platform 13.5

Oracle Enterprise Manager Base Platform 24.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.