HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46868Published Modified CNA oracle

CVE-2026-46868: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework)

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
7.2
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a high-severity vulnerability in the Extensibility Framework component of Oracle Enterprise Manager Base Platform, affecting versions 13.5 and 24.1. The vulnerability is reachable over the network via HTTPS and requires a high-privileged (administrative) account to exploit, with no victim interaction needed. Successful exploitation gives an attacker full control over the affected platform, including access to all data, the ability to modify configuration, and the ability to disrupt service availability. No fix version has been published yet; HarborGuard tracks the advisory and will surface a patched-image rebuild the moment Oracle publishes a fix.

HarborGuard Coverage

Detection

Detection for CVE-2026-46868 is available across every HarborGuard environment. The CVE is ingested from upstream feeds within minutes of publication and matched against customer images, including custom-built images derived from Oracle Enterprise Manager Base Platform 13.5 or 24.1.

Available
Triage

Triage is available using the CVSS 3.1 base score of 7.2 (HIGH), weighted against each customer organization's compliance policy to prioritize routing. Findings are surfaced to the appropriate team inbox within each customer environment based on configured ownership rules.

Available
Patch

Because no upstream fix has been published, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment a fix version is released. In the meantime, customers can apply compensating controls such as network-policy isolation to restrict HTTPS access to the Enterprise Manager management plane to known administrative hosts only.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle Enterprise Manager instance over the network via HTTPS; internet or internal network exposure to the management interface is sufficient.

  • AuthenticationRequired

    A high-privileged (administrative) account is required; the attacker must possess or compromise admin credentials before exploitation is possible.

  • Victim interactionNot required

    No action from any other user or administrator is needed to complete the attack.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other variable environmental factors.

Blast Radius

  • An attacker gains full read access to all data managed by the Enterprise Manager platform, including monitored target credentials, configuration data, and stored monitoring metadata.
  • An attacker can modify Enterprise Manager configuration, job definitions, and target management policies, allowing persistent changes to monitored infrastructure.
  • An attacker can crash or fully disable the Enterprise Manager service, eliminating visibility into the monitored infrastructure.
  • Full platform takeover is possible, meaning the attacker can use the compromised Enterprise Manager instance as a pivot point to interact with all registered managed targets.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-46868 is active for all customer environments scanning images built on Oracle Enterprise Manager Base Platform 13.5 or 24.1. Because Oracle has not yet published a fix version, no patched-image rebuild is available at this time. HarborGuard re-evaluates the upstream Oracle advisory on every ingest cycle; when a fix is released, a patched-image rebuild will become available automatically, and customers with auto-remediation enabled will receive a regression-tested rebuild with a PR opened against affected workloads. Until then, recommended compensating controls include applying Kubernetes or host-level network policies to restrict HTTPS access to the Enterprise Manager management interface to a defined allowlist of administrative source addresses, and auditing admin-account access logs for anomalous activity.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Enterprise Manager Base Platform
    13.5 · 24.1
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
References