Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Agent Next Gen component of Oracle Enterprise Manager Base Platform and allows a low‑privileged attacker to execute code and compromise the platform. If successfully exploited, the attacker can fully take control, leading to complete loss of confidentiality, integrity, and availability of the system. The CVSS vector indicates a network‑based attack with low authentication and no user interaction, confirming the high impact of this flaw.

Affected Systems

Oracle Corporation’s Oracle Enterprise Manager Base Platform is affected in versions 13.5 and 24.1. The platform is used for monitoring and managing enterprise IT infrastructure, and the vulnerability specifically targets the Agent Next Gen component.

Risk and Exploitability

The CVSS base score of 8.8 reflects a high severity, while the EPSS score of less than 1% suggests that exploitation probability is currently very low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based SSH connection that an attacker with low privileges can use to log into the platform and then exploit the Agent Next Gen component to gain full control. Without mitigation, an adversary could compromise the entire management platform.

Generated by OpenCVE AI on June 17, 2026 at 20:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Enterprise Manager patch that addresses the Agent Next Gen vulnerability (check the Oracle security advisory for the specific fix).
  • Restrict SSH access to the Enterprise Manager servers to only trusted IP addresses or VPN endpoints and enforce strong authentication methods to limit low‑privileged user reach.
  • Enable monitoring and alerts for suspicious SSH activity and anomalous process execution on the Enterprise Manager platform so that potential exploitation attempts can be detected early.

Generated by OpenCVE AI on June 17, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:54:49.377Z

Reserved: 2026-05-18T15:55:10.307Z

Link: CVE-2026-46864

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T23:00:05Z

Weaknesses

No weakness.