Data Compromise Risk in Oracle Enterprise Manager Base Platform
CVE-2026-46999

7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-46999?

A vulnerability in the Oracle Enterprise Manager Base Platform, specifically within the Discovery Framework component, poses significant risks. Unauthenticated attackers with network access via HTTPS can exploit this vulnerability, enabling them to create, modify, or delete critical data. This flaw affects versions 13.5 and 24.1, entailing unauthorized read access to sensitive information and the potential for causing partial denial of service. Organizations utilizing Oracle Enterprise Manager Base Platform must prioritize remediation to enhance their security posture.

Affected Version(s)

Oracle Enterprise Manager Base Platform 13.5

Oracle Enterprise Manager Base Platform 24.1

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.