A critical vulnerability, CVE-2026-46854, has been identified in Oracle Enterprise Manager Base Platform, specifically within the Target Management component. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise the affected system. The supported versions impacted are 13.5 and 24.1. While the vulnerability resides in the Oracle Enterprise Manager Base Platform, successful exploitation may lead to significant impacts on additional products due to a scope change. The CVSS 3.1 score of 9.9 indicates a high severity level, with the vulnerability being easily exploitable. Organizations utilizing the affected versions of Oracle Enterprise Manager Base Platform are strongly advised to apply the latest security patches provided by Oracle to mitigate this risk. Failure to address this vulnerability could result in unauthorized access and potential system takeover. Security teams should prioritize this remediation to prevent potential exploitation by threat actors targeting this specific vulnerability.
CRITICAL
CVSS 9.9
CVE-2026-46854
2026-08-23
Critical Vulnerability in Oracle Enterprise Manager Base Platform (CVE-2026-46854)
A critical vulnerability (CVE-2026-46854) allows low-privileged attackers to take over Oracle Enterprise Manager Base Platform via HTTP. Affects versions 13.5 and 24.1. CVSS 9.9. Immediate patching advised.