Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Easily exploitable vulnerability in the Metadata Plugin of Oracle Enterprise Manager Base Platform allows an unauthenticated attacker with network access over HTTP to compromise the platform. The vulnerability requires human interaction from another individual, typically by convincing them to access a special URL or trigger a request. Successful exploitation can result in full takeover of the platform, compromising confidentiality, integrity and availability.

Affected Systems

This affects Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. The issue is confined to the Metadata Plugin component but can impact other integrated products due to the change of scope.

Risk and Exploitability

The CVSS 3.1 base score of 9.6 indicates a critical severity, while an EPSS score below 1% suggests a low probability of exploitation under current conditions. The vulnerability is not listed in CISA’s KEV catalog, but because it requires an additional authenticated user to interact, it may be exploit limited. Nonetheless, the potential impact of complete platform compromise warrants immediate attention.

Generated by OpenCVE AI on June 17, 2026 at 19:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Enterprise Manager Base Platform patch that contains the fix for CVE-2026-46853.
  • Restrict HTTP access to the Metadata Plugin endpoint to privileged users or internal networks, or implement firewall rules to block unauthorized traffic.
  • Configure logging and monitor for suspicious HTTP requests targeting the plugin; investigate any anomalous activity.

Generated by OpenCVE AI on June 17, 2026 at 19:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:18:43.358Z

Reserved: 2026-05-18T15:55:10.306Z

Link: CVE-2026-46853

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T01:00:15Z

Weaknesses

No weakness.