Unauthenticated Access Vulnerability in Oracle Enterprise Manager for Fusion Middleware
CVE-2026-83355

9.8CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83355?

A vulnerability in the Oracle Enterprise Manager for Fusion Middleware component exposes supported versions to unauthenticated access through HTTP. This easily exploitable flaw allows an attacker with network access to launch an attack, potentially leading to a full compromise of the Oracle Enterprise Manager. The impacted versions, 13.5 and 24.1, require immediate attention to mitigate the risks associated with unauthorized access, which could severely impact confidentiality, integrity, and availability of the system.

Affected Version(s)

Oracle Enterprise Manager for Fusion Middleware 13.5

Oracle Enterprise Manager for Fusion Middleware 24.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.