CVE-2026-46853: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin)
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 9.6
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A cross-site scripting or script-injection class vulnerability (scope-changing, unauthenticated) affects the Metadata Plugin component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. The flaw is reachable over HTTP from any network location without credentials, but requires a victim to interact with attacker-controlled content, and the CVSS scope-change flag indicates a successful attack can break out of the affected component and compromise adjacent resources. Exploitation grants full takeover of the Oracle Enterprise Manager Base Platform instance, including complete read access, data modification, and service disruption. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix version.
HarborGuard Coverage
Detection capability for CVE-2026-46853 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Oracle Enterprise Manager Base Platform components.
AvailableHarborGuard scores this CVE at CVSS 9.6 (Critical) and surfaces it accordingly in each customer's vulnerability dashboard, weighted against that environment's compliance policy to route the alert to the appropriate team inbox.
AvailableNo fix version has been published by Oracle for this CVE; HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and PR against affected workloads will be triggered without manual intervention once a fix version becomes available.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle Enterprise Manager Base Platform service over the network via HTTP; no local or physical access is assumed.
- AuthenticationNot required
No credentials of any kind are needed; the attacker can interact with the vulnerable component as an unauthenticated user.
- Victim interactionRequired
A person other than the attacker must take an action (such as clicking a malicious link or visiting an attacker-crafted page) for the exploit to succeed.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other variable environmental factors.
Blast Radius
- A successful attacker reads all data accessible to Oracle Enterprise Manager Base Platform, including managed target credentials, monitoring configurations, and stored session tokens.
- The attacker can modify persisted configuration data, managed target definitions, and job schedules within the platform.
- The attacker can crash or render the Oracle Enterprise Manager Base Platform service unavailable, disrupting monitoring and management of all connected targets.
- Because the CVSS scope changes, the attacker can pivot from the Enterprise Manager component to compromise additional products and systems that the platform manages or has credentials for.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix version for CVE-2026-46853, the standard rebuild-and-PR flow is not yet triggerable. HarborGuard monitors the Oracle advisory on every ingest cycle and will make a patched-image rebuild available and queue auto-remediation PRs (for customers with that option enabled) the moment a fix version is published. In the interim, compensating controls worth evaluating include network-policy rules that restrict HTTP access to the Oracle Enterprise Manager web interface to known, trusted source CIDRs; egress filtering to limit what the platform can reach if an attacker does achieve a scope-change pivot; and, where operationally feasible, temporarily disabling or isolating the Metadata Plugin component through Oracle's feature configuration options. Customers can also use HarborGuard's compliance-policy weighting to escalate this CVE to a blocking gate in CI/CD pipelines, preventing any new images containing affected versions of Oracle Enterprise Manager Base Platform from being promoted to production until a patch is available.
- Oracle Corporation / Oracle Enterprise Manager Base Platform13.5 · 24.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H