A critical vulnerability, CVE-2026-46852, has been identified in the Oracle Enterprise Manager Base Platform, specifically within the Metadata Plugin component. This vulnerability allows a low-privileged attacker with network access via HTTPS to compromise the affected system. Supported versions 13.5 and 24.1 of the Oracle Enterprise Manager Base Platform are impacted. The vulnerability is easily exploitable and could lead to full system takeover, with potential scope changes affecting additional products. The CVSS score of 9.9 reflects the high severity of this issue. Organizations utilizing the affected versions of the Oracle Enterprise Manager Base Platform should prioritize applying the latest security patches provided by Oracle. Immediate action is recommended to mitigate the risk of unauthorized access and potential system compromise. Users are advised to review Oracle's official advisory for detailed mitigation steps and ensure all systems are updated to the latest secure versions.
CRITICAL
CVSS 9.9
CVE-2026-46852
2026-08-24
Critical Vulnerability in Oracle Enterprise Manager Base Platform (CVE-2026-46852)
A critical vulnerability (CVE-2026-46852) allows low-privileged attackers to take over Oracle Enterprise Manager Base Platform via HTTPS. Affects versions 13.5 and 24.1 of the Metadata Plugin component.