Description
Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Agent). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager for Systems Infrastructure executes to compromise Oracle Enterprise Manager for Systems Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Agent component of Oracle Enterprise Manager for Systems Infrastructure. A low‑privileged user who can log on to the infrastructure can exploit this flaw to compromise the product. Successful exploitation would allow the attacker to take full control of the instance, compromising confidentiality, integrity, and availability. The weakness appears to be a privilege‑escalation misconfiguration rather than code injection or denial of service.

Affected Systems

Affected installations are Oracle Enterprise Manager for Systems Infrastructure version 13.5 and 24.1. These appear as separate product releases. Installations of any other version or product type are not known to be at risk.

Risk and Exploitability

The CVSS base score of 7.8 indicates a high severity local attack with low authentication and no user interaction. Exploitability is considered easy as the description states the flaw is easily exploitable. The EPSS is unavailable; the vulnerability is not currently listed in the CISA KEV. Attackers would need only local presence and low privilege to gain full control, making this a significant risk for exposed or shared environments.

Generated by OpenCVE AI on August 18, 2026 at 23:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle‑provided security patch for Oracle Enterprise Manager for Systems Infrastructure 13.5 and 24.1.
  • Restrict local logon privileges of non‑administrative users on systems that host Oracle Enterprise Manager for Systems Infrastructure.
  • Disable or isolate the Agent component if it is not required for business operations.
  • Monitor system logs for unusual activity related to Oracle Enterprise Manager for Systems Infrastructure.

Generated by OpenCVE AI on August 18, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Enterprise Manager Agent Allows Full Takeover
Weaknesses CWE-264
CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Agent). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager for Systems Infrastructure executes to compromise Oracle Enterprise Manager for Systems Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager For Systems Infrastructure
CPEs cpe:2.3:a:oracle:enterprise_manager_for_systems_infrastructure:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_for_systems_infrastructure:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager For Systems Infrastructure
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager For Systems Infrastructure
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:12.502Z

Reserved: 2026-07-08T15:51:55.593Z

Link: CVE-2026-60822

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:44.397

Modified: 2026-08-18T21:16:44.397

Link: CVE-2026-60822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:00:04Z

Weaknesses
  • CWE-264
  • CWE-732

    Incorrect Permission Assignment for Critical Resource