PatchSiren cyber security CVE debrief
CVE-2026-46997 Oracle Corporation CVE debrief
The CVE-2026-46997 vulnerability affects the Oracle Enterprise Manager Base Platform, specifically the Metadata Plugin component, impacting versions 13.5 and 24.1. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTPS, potentially leading to unauthorized creation, deletion, or modification of critical data or all Oracle Enterprise Manager Base Platform accessible data. The CVSS 3.1 Base Score is 6.5, indicating a medium severity level with integrity impacts. Security teams should review and apply Oracle's security patches for affected versions, implement compensating controls, and monitor for suspicious activity related to unauthorized data modifications.
- Vendor
- Oracle Corporation
- Product
- Oracle Enterprise Manager Base Platform
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-07
Who should care
Security teams responsible for Oracle Enterprise Manager Base Platform, administrators of affected versions (13.5 and 24.1), and teams handling vulnerability management and patching should prioritize this vulnerability. Additionally, operators and platform administrators who oversee the affected systems, as well as security teams focusing on vulnerability management and remediation efforts, should be aware of the potential impacts and take necessary defensive measures to mitigate the risk of unauthorized data modifications and ensure the integrity of critical data accessible through the platform. This includes reviewing inventory of affected systems, prioritizing remediation, and verifying the implementation of compensating controls to monitor and restrict access to critical data while patches are being applied or verified. Furthermore, monitoring for suspicious activity related to unauthorized data modifications is crucial to prevent potential exploitation by attackers with network access via HTTPS. By taking these steps, organizations can reduce the risk associated with this medium-severity vulnerability and protect their Oracle Enterprise Manager Base Platform deployments from potential integrity impacts. The recommended actions include reviewing and applying Oracle's security patches, implementing compensating controls, verifying inventory of affected systems, and monitoring for suspicious activity related to unauthorized data modifications. These measures are essential for maintaining the security and integrity of critical data accessible through the Oracle Enterprise Manager Base Platform, especially given the ease of exploitation and potential for significant impact on data integrity. Therefore, it is crucial for the mentioned teams and administrators to collaborate on the remediation efforts and ensure that all necessary defensive measures are in place to mitigate the risks associated with CVE-2026-46997 effectively. This collaborative approach will help in minimizing the potential operational impact and ensuring the continued security and integrity of the affected systems and data. The vulnerability's medium severity and potential for integrity impacts,
Technical summary
A vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin) affects versions 13.5 and 24.1. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform, potentially leading to unauthorized creation, deletion, or modification of critical data or all Oracle Enterprise Manager Base Platform accessible data. The CVSS 3.1 Base Score is 6.5 (Integrity impacts), with a CVSS Vector of (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).
Defensive priority
Medium-priority defensive review recommended due to potential integrity impacts.
Recommended defensive actions
- Review and apply Oracle's security patches for affected versions of Enterprise Manager Base Platform.
- Implement compensating controls to monitor and restrict access to critical data.
- Verify inventory of affected systems and prioritize remediation.
- Monitor for suspicious activity related to unauthorized data modifications.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
Evidence from official CVE and NVD sources indicates a vulnerability in Oracle Enterprise Manager Base Platform, with a CVSS score of 6.5 and medium severity. The vulnerability affects versions 13.5 and 24.1, and allows a low-privileged attacker with network access via HTTPS to compromise the platform, potentially leading to unauthorized creation, deletion, or modification of critical data.
Official resources
-
CVE-2026-46997 CVE record
CVE.org
-
CVE-2026-46997 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:05.007Z and has not been modified since then.