CVE-2026-46864 Overview
CVE-2026-46864 affects the Oracle Enterprise Manager Base Platform, specifically the Agent Next Gen component. Oracle Enterprise Manager versions 13.5 and 24.1 are affected. A low-privileged attacker with network access via SSH can exploit this issue to compromise the platform. Successful exploitation can result in full takeover of Oracle Enterprise Manager Base Platform, impacting confidentiality, integrity, and availability. The flaw is categorized under CWE-284 (Improper Access Control). Oracle disclosed the issue in its June 2026 Critical Patch Update.
Critical Impact
Authenticated attackers with low privileges can achieve full takeover of Oracle Enterprise Manager Base Platform over the network via SSH.
Affected Products
- Oracle Enterprise Manager Base Platform 13.5.0.0
- Oracle Enterprise Manager Base Platform 24.1.0.0.0
- Component: Agent Next Gen
Discovery Timeline
- 2026-06-17 - CVE-2026-46864 published to NVD
- 2026-06-18 - Last updated in NVD database
- 2026-06-17 - Oracle published the June 2026 Critical Security Alert
Technical Details for CVE-2026-46864
Vulnerability Analysis
The vulnerability resides in the Agent Next Gen component of Oracle Enterprise Manager Base Platform. Oracle classifies the issue as easily exploitable, requiring only low privileges and no user interaction. The attack is delivered over the network via SSH, indicating that the agent communication or authentication pathway can be abused by an authenticated user with limited rights.
The weakness maps to CWE-284, Improper Access Control. Access controls in the Agent Next Gen component fail to adequately restrict actions a low-privileged user can perform. As a result, an attacker can escalate from limited SSH access to control over the management platform.
The EPSS probability is 0.432%, reflecting current exploitation likelihood data published on 2026-06-18.
Root Cause
The root cause is improper access control within the Agent Next Gen component. Oracle has not published implementation-level technical details. Based on the CVSS metrics, the affected interface accepts authenticated SSH input from a low-privileged user and processes it in a way that crosses trust boundaries. The vulnerability does not require user interaction and operates within a single security scope.
Attack Vector
An attacker requires network reachability to the SSH interface used by Agent Next Gen and a valid low-privileged account. After authenticating, the attacker issues operations that the access control layer should reject. Because the platform is a central management system, compromise propagates to all targets the platform supervises.
No verified public proof-of-concept exists at the time of writing. Refer to the Oracle Security Alert for vendor-confirmed technical context.
Detection Methods for CVE-2026-46864
Indicators of Compromise
- Unexpected SSH sessions to Oracle Enterprise Manager Agent Next Gen endpoints from low-privileged accounts
- New or modified administrative jobs, targets, or credentials registered through the platform without change-control records
- Outbound connections from the Enterprise Manager host to unfamiliar destinations following SSH activity
- Creation of new operating system accounts or privilege grants on the OMS host or managed targets
Detection Strategies
- Audit Enterprise Manager emctl and agent logs for unusual command sequences originating from non-administrative accounts
- Correlate SSH authentication events on the OMS host with subsequent privileged operations inside Enterprise Manager
- Baseline normal Agent Next Gen behavior and flag deviations in job submission, plugin deployment, or credential use
Monitoring Recommendations
- Forward SSH, agent, and OMS audit logs to a centralized analytics platform with retention sufficient for incident review
- Alert on privilege grants, role changes, and credential modifications inside Oracle Enterprise Manager
- Monitor for lateral movement from the OMS host to managed databases and middleware tiers
How to Mitigate CVE-2026-46864
Immediate Actions Required
- Apply the Oracle June 2026 Critical Patch Update to all Oracle Enterprise Manager 13.5 and 24.1 installations
- Inventory all low-privileged accounts with SSH access to the OMS host and revoke any that are unnecessary
- Rotate credentials for accounts that could have reached the Agent Next Gen interface prior to patching
- Review audit logs for the period preceding patch deployment for signs of misuse
Patch Information
Oracle published the fix as part of the June 2026 Critical Security Alert. Administrators should consult the Oracle Security Alert advisory for the exact patch identifiers, prerequisite bundle patches, and rollout guidance for Enterprise Manager 13.5 and 24.1.
Workarounds
- Restrict network access to the Enterprise Manager SSH interface to administrative jump hosts only
- Enforce multi-factor authentication on all accounts permitted to reach the OMS host
- Apply least privilege to operating system and Enterprise Manager roles, removing standing access where possible
- Segment the Enterprise Manager management network from general user networks
# Example: restrict SSH access to the OMS host to a management subnet
# /etc/hosts.allow
sshd: 10.10.50.0/24
# /etc/hosts.deny
sshd: ALL
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

