PatchSiren cyber security CVE debrief
CVE-2026-46865 Oracle Corporation CVE debrief
A high-severity vulnerability was discovered in Oracle Enterprise Manager Base Platform, affecting versions 13.5 and 24.1. The vulnerability, CVE-2026-46865, has a CVSS score of 8.2 and allows high-privileged attackers with logon access to compromise the platform. Successful attacks can result in takeover of Oracle Enterprise Manager Base Platform. This vulnerability is located in the Extensibility Framework component and has a significant impact on affected systems.
- Vendor
- Oracle Corporation
- Product
- Oracle Enterprise Manager Base Platform
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-18
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-18
Who should care
Organizations using Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 should prioritize patching this vulnerability to prevent potential compromise. This is crucial for operators, platform administrators, and security teams to ensure the security and integrity of their systems. They should assess their exposure, review access controls, and implement compensating controls if necessary.
Technical summary
The vulnerability, CVE-2026-46865, is located in the Extensibility Framework component of Oracle Enterprise Manager Base Platform, affecting versions 13.5 and 24.1. It has a CVSS vector of CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, indicating a high severity. High-privileged attackers with logon access to the infrastructure can exploit this vulnerability, potentially leading to a takeover of Oracle Enterprise Manager Base Platform. The vulnerability allows attackers to compromise the platform, impacting confidentiality, integrity, and availability.
Defensive priority
High priority should be given to patching this vulnerability due to its high severity and potential impact on affected systems. Organizations should review and update access controls to limit logon access to infrastructure and monitor Oracle Enterprise Manager Base Platform for suspicious activity. Implementing compensating controls to mitigate potential impact is also recommended until patches can be applied.
Recommended defensive actions
- Apply the patch from Oracle as soon as possible
- Review and update access controls to limit logon access to infrastructure
- Monitor Oracle Enterprise Manager Base Platform for suspicious activity
- Consider implementing compensating controls to mitigate potential impact
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record was published on 2026-06-17T10:54:04.170Z and modified on 2026-06-18T04:16:53.200Z. The NVD entry is currently Modified. This information is based on the provided source corpus. Further verification is recommended to confirm the accuracy of this information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46865 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46865
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46865 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46865
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspujun2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.