Description
Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager for Fusion Middleware. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Fusion Middleware. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an authentication bypass in the Metrics component of Oracle Enterprise Manager for Fusion Middleware that enables an unauthenticated attacker with network access over HTTP to take full control of the system. Successful exploitation results in remote code execution and full compromise of confidentiality, integrity, and availability. The flaw is reflected by the high CVSS 9.8 score, indicating a severe impact if exploited.

Affected Systems

Both version 13.5 and 24.1 of Oracle Enterprise Manager for Fusion flaw is specific to the Enterprise Manager product as distributed by Oracle.

Risk and Exploitability

The CVSS v3.1 Base Score is 9.8, with no user interaction and low attack complexity required. The EPSS score is below 1%, indicating a low probability of widespread exploitation, but the vulnerability is listed outside the CISA KEV catalog. The attack vector is inferred to be remote HTTP traffic, and the lack of authentication credentials is a prerequisite for success.

Generated by OpenCVE AI on September 18, 2026 at 14:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for the affected versions of Enterprise Manager for Fusion Middleware.
  • Limit HTTP access to the Enterprise Manager port to trusted networks or hosts, implementing network segmentation or firewall rules.
  • If a patch is not yet available, block or disable the Metrics component or restrict HTTP access until remediation.
  • Monitor for unexpected authentication attempts and compromise indicators, and enable logging to detect potential exploitation.

Generated by OpenCVE AI on September 18, 2026 at 14:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authentication Bypass in Oracle Enterprise Manager Metrics

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager for Fusion Middleware. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Fusion Middleware. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager For Fusion Middleware
CPEs cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager For Fusion Middleware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager For Fusion Middleware
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:34.939Z

Reserved: 2026-08-31T15:40:57.354Z

Link: CVE-2026-83355

cve-icon Vulnrichment

Updated: 2026-09-15T22:44:42.714Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:49.020

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:00:10Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function