HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46864Published Modified CNA oracle

CVE-2026-46864: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen)

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An authentication-bypass-level remote exploit affects the Agent Next Gen component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. A low-privileged attacker with network access over SSH can reach the vulnerable component without requiring any special permissions or victim interaction. Successful exploitation results in full takeover of the platform, giving the attacker read, write, and disruption capabilities across the managed environment. No fix version has been published yet; HarborGuard tracks the Oracle advisory and will surface a patched-image rebuild the moment upstream ships a fix.

HarborGuard Coverage

Detection

Detection of CVE-2026-46864 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that package Oracle Enterprise Manager Base Platform components. Any image in a connected registry or CI pipeline running an affected version (13.5 or 24.1) is flagged automatically.

Available
Triage

HarborGuard is capable of scoring this finding at CVSS 8.8 HIGH and weighting it against each environment's compliance policy to determine ticket priority and escalation path. Triage routing is available to direct the alert to the appropriate team inbox within each customer organization based on image ownership and policy configuration.

Available
Patch

Because no upstream fix version has been published, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available the moment a fix is released. For customers with auto-remediation enabled, the rebuild, regression test run, and PR against affected workloads will trigger automatically at that point, with no manual intervention required.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Agent Next Gen service over the network via SSH; the component is exposed to network-accessible attack paths.

  • AuthenticationRequired

    A low-privilege account is sufficient; no administrative or elevated credentials are needed to trigger the vulnerability.

  • Victim interactionNot required

    No user action or social engineering is needed; the attacker can exploit the vulnerability entirely on their own.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory layout dependencies, or environmental prerequisites.

Blast Radius

  • A successful attacker gains full read access to all data managed by Oracle Enterprise Manager Base Platform, including credentials, monitoring configurations, and target host metadata.
  • The attacker can write or modify persisted platform data, including job definitions, agent configurations, and policies controlling managed targets.
  • The attacker can crash or disable the Enterprise Manager platform and its Agent Next Gen component, cutting off monitoring and management of all connected hosts.
  • Because the platform manages infrastructure targets, a takeover effectively extends attacker reach to every host and service under Enterprise Manager supervision.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46864, the platform monitors the Oracle advisory on every ingest cycle and will surface a patched-image rebuild the moment an upstream fix is released. In the interim, customers can apply compensating controls through HarborGuard policy: network-policy isolation rules can restrict SSH access to the Agent Next Gen component to trusted source CIDRs only, and egress filtering can limit the component's outbound reach to reduce post-compromise lateral movement. For customers with auto-remediation enabled, a rebuild plus regression test run plus PR against affected workloads will trigger automatically when the upstream patch becomes available, with no manual steps required. Environments that cannot wait for the upstream fix are encouraged to gate Agent Next Gen exposure behind a bastion or VPN and to audit which low-privilege accounts hold SSH access to the affected versions (13.5 and 24.1).

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Enterprise Manager Base Platform
    13.5 · 24.1
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References