Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Agent Next Gen component of Oracle Enterprise Manager Base Platform allows an attacker to send HTTPS requests without any authentication and take complete control of the platform. The weakness, classified as CWE-284 Improper Access Control, results in loss of confidentiality, integrity and availability for all data and services managed by the platform. Successful exploitation gives the attacker full administrative rights to the system, enabling arbitrary configuration, data exfiltration, or further lateral movement within the managed environment.

Affected Systems

The affected vendor is Oracle Corporation, specifically the Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. These releases expose the Agent Next Gen service via HTTPS without enforcing proper access control. Earlier or later versions not listed in the known affected versions are not known to be impacted.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 marks this as critical, with a full impact on confidentiality, integrity and availability. The EPSS score is less than 1% indicating a low current exploitation probability, and the vulnerability has not been listed in the CISA KEV catalog. However, any system exposed to the public or untrusted networks can be targeted trivially: an attacker only needs network access to the HTTPS interface and no credentials to succeed, making the risk high for exposed installations.

Generated by OpenCVE AI on August 3, 2026 at 00:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the July 2026 Oracle patch or upgrade the Enterprise Manager Base Platform to a version released after the patch to address the access control flaw
  • Restrict HTTPS access to the Enterprise Manager Base Platform to trusted IP ranges or enforce VPN connectivity to limit exposure to potential attackers
  • Enable and regularly review audit logs for the Agent Next Gen service to detect and respond to unauthenticated access attempts

Generated by OpenCVE AI on August 3, 2026 at 00:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Enables Platform Compromise in Oracle Enterprise Manager

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Oracle Enterprise Manager Base Platform: Unauthenticated HTTPS Agent Vulnerability

Fri, 24 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Oracle Enterprise Manager Base Platform: Unauthenticated HTTPS Agent Vulnerability

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T13:47:27.963Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46994

cve-icon Vulnrichment

Updated: 2026-07-23T13:47:09.920Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses