Oracle Enterprise Manager Base Platform contains a critical, network-exploitable vulnerability (CVSS 9.1) that lets a low-privileged attacker compromise the platform and reach beyond it into additional products.
What Is It
CVE-2026-46989 is a vulnerability in the UI Framework component of Oracle Enterprise Manager Base Platform, part of Oracle Enterprise Manager. Per Oracle's advisory, it is an easily exploitable flaw that allows a low-privileged attacker with network access via HTTPS to compromise the platform. Notably, the vulnerability carries a scope change: while it resides in Oracle Enterprise Manager Base Platform, successful attacks may significantly impact additional products. It carries a CVSS 3.1 base score of 9.1 (CRITICAL), vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L.
Why It Matters
The combination of network attack vector, low attack complexity, only low privileges required, and no user interaction makes this straightforward to exploit. Successful attacks can result in unauthorized access to critical data, up to complete access to all Oracle Enterprise Manager Base Platform accessible data, as well as unauthorized update, insert, or delete of some accessible data, and the ability to cause a partial denial of service. Because Oracle Enterprise Manager is used to manage broad swaths of enterprise infrastructure, the scope-change impact on additional products raises the stakes considerably.
What's Vulnerable
- Product: Oracle Enterprise Manager Base Platform (component: UI Framework)
- Affected supported versions: 13.5 and 24.1
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026). Note: the supplied source material contains no CISA KEV entry, so there is no confirmation of active exploitation in the wild at this time.