Unauthenticated Remote Code Execution Vulnerability in Oracle Enterprise Manager by Oracle
CVE-2026-46994

9.8CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-46994?

An unauthenticated vulnerability exists in the Oracle Enterprise Manager Base Platform, specifically within the Agent Next Gen component. This flaw allows an attacker with network access via HTTPS to exploit the system easily. If successfully exploited, the attacker could take control of the Oracle Enterprise Manager Base Platform. The supported versions vulnerable to this issue are 13.5 and 24.1, significantly risking the confidentiality, integrity, and availability of affected systems. Organizations using these versions should apply security patches promptly to mitigate potential risks.

Affected Version(s)

Oracle Enterprise Manager Base Platform 13.5

Oracle Enterprise Manager Base Platform 24.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.