CVE-2026-46858: Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics)
Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application Performance Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all APM - Application Performance Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of APM - Application Performance Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
Metrics
- CVSS v3.1
- 9.1
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An unauthenticated remote attacker can exploit a critical integrity and availability flaw in the JADM and JVM Diagnostics component of Oracle Enterprise Manager APM (Application Performance Management) versions 13.5 and 24.1 over HTTP, requiring no credentials and no victim interaction. Successful exploitation allows the attacker to create, delete, or modify any data accessible to APM and to cause a complete denial of service through hangs or repeated crashes. No fix version has been published by Oracle; HarborGuard tracks the advisory and will surface a patched-image rebuild the moment upstream ships a fix.
HarborGuard Coverage
Detection of CVE-2026-46858 is available across every HarborGuard environment: the CVE is ingested from Oracle and NVD advisory feeds within minutes of publication and matched against customer images, including custom-built images that bundle Oracle Enterprise Manager APM components, across all connected registries and CI/CD pipelines.
AvailableTriage is available with the CVSS 3.1 base score of 9.1 (Critical) applied automatically, weighted further by each customer organization's compliance policy to prioritize affected workloads; findings are routed to the appropriate team inbox within each customer environment based on configured ownership rules.
AvailableBecause Oracle has not yet published a fix version, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and pull request against affected workloads will be triggered without manual intervention once a fix version exists.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the APM service over the network via HTTP; no local access or physical proximity is needed.
- AuthenticationNot required
No credentials of any privilege level are required; the vulnerability is exploitable by any unauthenticated party with network access.
- Victim interactionNot required
No user action or social engineering is needed; the attacker operates entirely without involving a legitimate user.
- Attack complexityDetail
Exploitation is straightforward and condition-free, with no race conditions or environmental prerequisites required for a reliable attack.
Blast Radius
- The attacker can create, overwrite, or delete any data stored or accessible within APM, including JVM diagnostics records, performance metrics, and configuration data.
- The attacker can corrupt or fabricate monitoring data, undermining the accuracy of all performance and availability reporting fed by the APM component.
- The attacker can trigger a complete denial of service by causing the APM service to hang or crash repeatedly, disrupting visibility into all monitored Java workloads.
- Downstream systems or teams relying on APM data for alerting and capacity decisions lose trustworthy signal for the duration of an active attack.
How HarborGuard Handles This
Available on HarborGuard: continuous monitoring of the Oracle and NVD advisory feeds means CVE-2026-46858 is matched against all customer images, including custom Oracle Enterprise Manager builds, within minutes of any advisory update. Because no upstream fix exists as of the publication date, HarborGuard cannot yet generate a patched-image rebuild; instead, the advisory is re-evaluated on every ingest cycle and a rebuild will become available automatically the moment Oracle ships a fix version. In the interim, customers can apply compensating controls available through HarborGuard's policy engine: network-policy rules that restrict HTTP access to APM endpoints to known, trusted source CIDRs only; egress filtering to limit lateral paths from a compromised APM node; and compliance alerts that flag any image running versions 13.5 or 24.1 as requiring immediate review. For customers with auto-remediation enabled, the patched rebuild, regression-test run, and pull request against affected workloads will be triggered automatically once Oracle publishes a fix, with median time from CVE publication to merged patch PR for critical-severity issues around 90 minutes under that configuration.
- Oracle Corporation / APM - Application Performance Management13.5 · 24.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H