SYS::ONLINE
Wasteland.
Briefs1408
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-46989 2026-07-21

CVE-2026-46989: Critical Flaw in Oracle Enterprise Manager Base Platform

"Oracle Enterprise Manager Base Platform contains a critical, network-exploitable vulnerability (CVSS 9.1) that lets a low-privileged attacker compromise the platform and reach beyond it into additional products."

Oracle Enterprise Manager Base Platform contains a critical, network-exploitable vulnerability (CVSS 9.1) that lets a low-privileged attacker compromise the platform and reach beyond it into additional products.

What Is It

CVE-2026-46989 is a vulnerability in the UI Framework component of Oracle Enterprise Manager Base Platform, part of Oracle Enterprise Manager. Per Oracle's advisory, it is an easily exploitable flaw that allows a low-privileged attacker with network access via HTTPS to compromise the platform. Notably, the vulnerability carries a scope change: while it resides in Oracle Enterprise Manager Base Platform, successful attacks may significantly impact additional products. It carries a CVSS 3.1 base score of 9.1 (CRITICAL), vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L.

Why It Matters

The combination of network attack vector, low attack complexity, only low privileges required, and no user interaction makes this straightforward to exploit. Successful attacks can result in unauthorized access to critical data, up to complete access to all Oracle Enterprise Manager Base Platform accessible data, as well as unauthorized update, insert, or delete of some accessible data, and the ability to cause a partial denial of service. Because Oracle Enterprise Manager is used to manage broad swaths of enterprise infrastructure, the scope-change impact on additional products raises the stakes considerably.

What's Vulnerable

Patch Status

Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026). Note: the supplied source material contains no CISA KEV entry, so there is no confirmation of active exploitation in the wild at this time.

Sources