Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE exposes an authorization bypass in the Enterprise Config Management component of Oracle Enterprise Manager Base Platform, allowing an attacker with low‑privileged or local access to the host to perform unauthorized update, insert, or delete operations on platform data, as well as read restricted data. The weakness stems from improper validation of user privileges (CWE‑284) and results in both confidentiality and integrity compromise of the platform’s configuration and operational information.

Affected Systems

Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. These are the only versions listed in the CNA release and are the ones where the vulnerability is present.

Risk and Exploitability

The CVSS 3.1 score of 4.4 indicates low severity, and the EPSS score of less than 1 % implies a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local or low‑privileged access to the host running the base platform; thus the likely attack vector is a low‑privileged local attacker or compromised service account.

Generated by OpenCVE AI on August 4, 2026 at 05:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Enterprise Manager Base Platform patch for versions 13.5 and 24.1, available from the Oracle Security Alerts page for CPU Jul 2026.
  • Restrict the use of local user accounts on the infrastructure that hosts Oracle Enterprise Manager to the minimum necessary privileges, and enforce strict role‑based access controls for configuration changes.
  • Configure comprehensive audit logging and regularly review log entries for abnormal create, modify, or delete actions involving Oracle Enterprise Manager configuration and data.

Generated by OpenCVE AI on August 4, 2026 at 05:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle Enterprise Manager Base Platform

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle Enterprise Manager Base Platform

Mon, 27 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Enabling Unauthorized Data Modification in Oracle Enterprise Manager Base Platform

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Enabling Unauthorized Data Modification in Oracle Enterprise Manager Base Platform

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T13:37:03.370Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46991

cve-icon Vulnrichment

Updated: 2026-07-23T13:36:00.855Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses