Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Enterprise Manager Base Platform’s Extensibility Framework contains a flaw that allows a high‑privileged attacker who has already logged on to the host machine to gain complete control of the platform. Once exploited, the attacker can read, modify, and delete any sensitive data and disrupt data collection processes, leading to confidentiality, integrity, and availability loss. This weakness is consistent with improper privilege management and results in a scope change when the platform’s internal components are compromised.

Affected Systems

Oracle Enterprise Manager Base Platform, versions 13.5 and 24.1, as identified by the CNA and listed in the affected‑versions field.

Risk and Exploitability

The CVSS base score of 8.2 denotes a high severity, while the EPSS score of less than 1 % indicates that, at present, exploitation is unlikely to occur in the wild. The vulnerability is not included in the CISA KEV catalog. The attack requires a local attacker with elevated privileges; therefore, an internal threat actor who can gain host‑level access can exploit the flaw, potentially taking over the entire platform. No public exploits are reported, but the critical scope and the ability to fully compromise the system elevate the risk for affected environments.

Generated by OpenCVE AI on June 17, 2026 at 19:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Enterprise Manager patch referenced in the June 2026 security alert
  • Disable or tightly restrict access to the Extensibility Framework API endpoints
  • Remove or isolate any unused or deprecated modules that expose the framework

Generated by OpenCVE AI on June 17, 2026 at 19:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:55:56.241Z

Reserved: 2026-05-18T15:55:10.308Z

Link: CVE-2026-46865

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T03:15:02Z

Weaknesses

No weakness.