Here is the revised article body:
CVE-2026-46994: Critical Unauthenticated Takeover in Oracle Enterprise Manager
A critical, easily exploitable flaw in Oracle Enterprise Manager Base Platform lets an unauthenticated attacker take over the product over the network, earning a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-46994 is a vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager, specifically in the Agent Next Gen component. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTPS to compromise the platform. A successful attack can result in complete takeover of Oracle Enterprise Manager Base Platform.
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting a network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
With a base score of 9.8 (CRITICAL) and a maximum exploitability sub-score of 3.9, no authentication and no user interaction are needed; an attacker only needs network reachability to the affected HTTPS service. Because Oracle Enterprise Manager is a central management platform, a full takeover can hand an attacker broad control over the environments it administers.
What's Vulnerable
- Product: Oracle Enterprise Manager Base Platform (component: Agent Next Gen)
- Vendor: Oracle Corporation
- Affected versions: 13.5 and 24.1
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Administrators running affected versions 13.5 or 24.1 should apply the fixes referenced in the Oracle Critical Patch Update Advisory (cpujul2026) as soon as possible.
Note: The supplied CISA KEV entry is empty, so there is no confirmation of active exploitation in the provided source material.