A critical vulnerability, CVE-2026-46855, has been identified in the Oracle Enterprise Manager Base Platform, specifically within the Metadata Plugin component. This vulnerability allows a low-privileged attacker with network access via HTTPS to compromise the platform. Supported versions affected include 13.5 and 24.1 of the Oracle Enterprise Manager Base Platform. While the vulnerability is confined to the Base Platform, successful exploitation may lead to significant impacts on additional products. The CVSS score of 9.9 indicates a high severity level, emphasizing the critical nature of this issue. Organizations utilizing these affected versions are strongly advised to apply the necessary patches or updates provided by Oracle to mitigate the risk of exploitation. This vulnerability poses a significant threat to the integrity and security of systems relying on the Oracle Enterprise Manager Base Platform. Immediate action is recommended to prevent potential unauthorized access and system compromise.
CRITICAL
CVSS 9.9
CVE-2026-46855
2026-08-24
Critical Vulnerability in Oracle Enterprise Manager Base Platform (CVE-2026-46855)
A critical vulnerability (CVE-2026-46855) allows low-privileged attackers to take over Oracle Enterprise Manager Base Platform via HTTPS. Affects versions 13.5 and 24.1 of the Metadata Plugin component.