CVE-2026-46875 Overview
CVE-2026-46875 affects the Deployment Library component of Oracle Enterprise Manager Base Platform. The flaw allows a high-privileged attacker with network access over HTTPS to compromise the platform. Successful exploitation results in full takeover of Oracle Enterprise Manager Base Platform.
The vulnerability carries a scope-change classification, meaning attacks can significantly impact additional products beyond the vulnerable component. Oracle classifies the issue under [CWE-284: Improper Access Control]. Affected releases include versions 13.5 and 24.1, both widely deployed in enterprise database management environments.
Critical Impact
Authenticated attackers can take over Oracle Enterprise Manager Base Platform and pivot to additional managed Oracle products through scope change.
Affected Products
- Oracle Enterprise Manager Base Platform 13.5.0.0
- Oracle Enterprise Manager Base Platform 24.1.0.0.0
- Deployment Library component
Discovery Timeline
- 2026-06-17 - CVE-2026-46875 published to NVD
- 2026-06-18 - Last updated in NVD database
- 2026-06-17 - Oracle Critical Security Patch Update advisory released
Technical Details for CVE-2026-46875
Vulnerability Analysis
The vulnerability resides in the Deployment Library component of Oracle Enterprise Manager Base Platform. Oracle Enterprise Manager (OEM) is a centralized management platform used to monitor and administer Oracle databases, middleware, and applications across enterprise environments. The Deployment Library handles provisioning bundles, software components, and deployment procedures used to push configurations to managed targets.
An attacker with high privileges on the OEM platform can abuse the Deployment Library over HTTPS to compromise the management server. Because OEM holds credentials and connectivity to downstream managed systems, a successful attack expands beyond the management plane and reaches additional Oracle products, reflecting the scope change in the CVSS vector.
Root Cause
Oracle classifies the issue under [CWE-284: Improper Access Control]. The Deployment Library does not adequately restrict actions available to authenticated users at elevated privilege levels. The control gap allows authorized users to perform operations that should require additional validation, leading to platform takeover.
Attack Vector
Exploitation requires network reachability to the OEM HTTPS interface and valid high-privileged credentials. No user interaction is required. The attacker submits requests to the Deployment Library endpoint to trigger the unauthorized operations. Public proof-of-concept code is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
For technical specifics, refer to the Oracle Security Alert.
Detection Methods for CVE-2026-46875
Indicators of Compromise
- Unexpected deployment procedures, software library entries, or provisioning bundles created by privileged OEM accounts.
- HTTPS requests to OEM Deployment Library endpoints from administrative accounts outside normal change windows.
- New or modified OEM agents deployed to targets without a corresponding approved change ticket.
Detection Strategies
- Audit SYSMAN schema tables for Deployment Library modifications and correlate against approved change records.
- Monitor OEM emoms.log and emctl audit trails for high-privileged user activity referencing the Deployment Library.
- Alert on lateral movement signals from the OEM host toward managed database targets immediately after Deployment Library activity.
Monitoring Recommendations
- Forward OEM application logs and OS-level telemetry into a centralized SIEM with retention sufficient for forensic review.
- Baseline normal Deployment Library usage per administrator and alert on deviation in frequency or off-hours activity.
- Track outbound connections from the OEM management server to inventory unexpected target interactions.
How to Mitigate CVE-2026-46875
Immediate Actions Required
- Apply the Oracle Critical Patch Update from June 2026 to Oracle Enterprise Manager Base Platform 13.5 and 24.1.
- Restrict network access to the OEM HTTPS console to administrative subnets and jump hosts only.
- Audit and reduce the number of accounts holding EM_ALL_ADMINISTRATOR or equivalent high-privilege roles.
- Rotate credentials for OEM administrative accounts and review preferred credentials stored in OEM.
Patch Information
Oracle addressed CVE-2026-46875 in the June 2026 Critical Patch Update. Administrators must apply the platform-specific bundle patches for Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. Full remediation details are available in the Oracle Security Alert.
Workarounds
- Limit Deployment Library access to a minimal set of trusted administrators until patches are applied.
- Place the OEM management server behind a reverse proxy enforcing IP allowlists and multi-factor authentication.
- Enable detailed audit logging in OEM and review Deployment Library actions daily during the remediation window.
# Apply Oracle Enterprise Manager bundle patch using OMSPatcher
$ORACLE_HOME/OMSPatcher/omspatcher apply <patch_directory>
$ORACLE_HOME/OMSPatcher/omspatcher lspatches
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

