CVE-2026-46990: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of serv
CVE-2026-46990 is a high-severity vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It allows an unauthenticated attacker with network access via HTTP to perform unauthorized read, update, insert, or delete operations on accessible data, and to cause a partial denial of service. The vulnerability affects confidentiality, integrity, and availability of the platform. Oracle has published a Critical Patch Update advisory referencing this and many other vulnerabilities but does not explicitly confirm a patch for this specific issue in the provided advisory content.
AI Analysis
Technical Summary
This vulnerability in the Oracle Enterprise Manager Base Platform (component: Enterprise Config Management) allows an unauthenticated attacker with network access via HTTP to compromise the platform. Successful exploitation can lead to unauthorized modification (update, insert, delete) and unauthorized reading of some accessible data, as well as partial denial of service. The CVSS 3.1 base score is 7.3 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L, indicating network attack vector, low attack complexity, no privileges or user interaction required, and impacts on confidentiality, integrity, and availability. Affected versions explicitly include 13.5 and 24.1. The vendor advisory is a general Critical Patch Update for July 2026 covering many products but does not specifically confirm patch availability or remediation details for this vulnerability.
Potential Impact
The vulnerability allows an unauthenticated remote attacker to gain unauthorized read and write access to some data within Oracle Enterprise Manager Base Platform, potentially leading to data compromise and partial denial of service. This impacts confidentiality, integrity, and availability of the affected system. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Oracle has released a Critical Patch Update advisory in July 2026 covering multiple vulnerabilities. However, the advisory content provided does not explicitly confirm the availability of a patch or fix for CVE-2026-46990. Customers are strongly advised to review the Oracle Critical Patch Update advisory at https://www.oracle.com/security-alerts/cpujul2026.html for the latest patch availability and installation instructions. Until a patch is confirmed, monitor Oracle's advisories for updates. No vendor-stated 'no action required' or 'already mitigated' guidance is present.
CVE-2026-46990: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of serv
Description
CVE-2026-46990 is a high-severity vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It allows an unauthenticated attacker with network access via HTTP to perform unauthorized read, update, insert, or delete operations on accessible data, and to cause a partial denial of service. The vulnerability affects confidentiality, integrity, and availability of the platform. Oracle has published a Critical Patch Update advisory referencing this and many other vulnerabilities but does not explicitly confirm a patch for this specific issue in the provided advisory content.
CVSS v3.1
Score 7.3high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in the Oracle Enterprise Manager Base Platform (component: Enterprise Config Management) allows an unauthenticated attacker with network access via HTTP to compromise the platform. Successful exploitation can lead to unauthorized modification (update, insert, delete) and unauthorized reading of some accessible data, as well as partial denial of service. The CVSS 3.1 base score is 7.3 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L, indicating network attack vector, low attack complexity, no privileges or user interaction required, and impacts on confidentiality, integrity, and availability. Affected versions explicitly include 13.5 and 24.1. The vendor advisory is a general Critical Patch Update for July 2026 covering many products but does not specifically confirm patch availability or remediation details for this vulnerability.
Potential Impact
The vulnerability allows an unauthenticated remote attacker to gain unauthorized read and write access to some data within Oracle Enterprise Manager Base Platform, potentially leading to data compromise and partial denial of service. This impacts confidentiality, integrity, and availability of the affected system. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Oracle has released a Critical Patch Update advisory in July 2026 covering multiple vulnerabilities. However, the advisory content provided does not explicitly confirm the availability of a patch or fix for CVE-2026-46990. Customers are strongly advised to review the Oracle Critical Patch Update advisory at https://www.oracle.com/security-alerts/cpujul2026.html for the latest patch availability and installation instructions. Until a patch is confirmed, monitor Oracle's advisories for updates. No vendor-stated 'no action required' or 'already mitigated' guidance is present.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- oracle
- Date Reserved
- 2026-05-18T15:55:10.315Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","vendor":"Oracle"}]
Threat ID: 6a5fe6c29c2644c7f8cb028e
Added to database: 07/21/2026, 21:38:10 UTC
Last enriched: 07/30/2026, 05:24:54 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.