Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-46993

CVE-2026-46993: Oracle Enterprise Manager Auth Bypass Flaw

CVE-2026-46993 is an authentication bypass vulnerability in Oracle Enterprise Manager Base Platform affecting versions 13.5 and 24.1. This critical flaw allows unauthorized data access and modification. Learn the technical details.

Published:

CVE-2026-46993 Overview

CVE-2026-46993 is an improper access control vulnerability [CWE-284] in the Agent Next Gen component of the Oracle Enterprise Manager Base Platform. Supported versions 13.5 and 24.1 are affected. A low-privileged attacker with network access over HTTPS can compromise the platform, and successful exploitation can extend beyond the vulnerable component through a scope change. The flaw permits unauthorized creation, deletion, or modification of critical data and full read access to all data accessible to Oracle Enterprise Manager Base Platform. Oracle addressed the issue in the July 2026 Critical Patch Update.

Critical Impact

Successful exploitation allows a network-based, low-privileged attacker to read and modify all data accessible to Oracle Enterprise Manager Base Platform and to impact adjacent products through scope change.

Affected Products

  • Oracle Enterprise Manager Base Platform version 13.5
  • Oracle Enterprise Manager Base Platform version 24.1
  • Agent Next Gen component of Oracle Enterprise Manager

Discovery Timeline

  • 2026-07-21 - CVE-2026-46993 published to NVD
  • 2026-07-23 - Last updated in NVD database
  • July 2026 - Oracle releases fix in the Oracle Security Alert July 2026

Technical Details for CVE-2026-46993

Vulnerability Analysis

CVE-2026-46993 resides in the Agent Next Gen component of Oracle Enterprise Manager Base Platform. The weakness is classified as improper access control [CWE-284]. An authenticated attacker with low privileges can send crafted HTTPS requests to the agent interface and bypass controls that should restrict data operations. The attack complexity is high, indicating specific conditions must be met before exploitation succeeds.

A scope change is present, which means exploitation impacts security-relevant components beyond the vulnerable one. Because Oracle Enterprise Manager centrally administers databases, middleware, and infrastructure fleets, a compromise of the agent tier can propagate to managed targets. The confidentiality and integrity impacts are high, while availability is not affected. EPSS currently reports a probability of 0.292% at the 21.329 percentile.

Root Cause

The root cause is improper enforcement of access controls in the Agent Next Gen component. Authorization decisions for privileged actions do not adequately validate the caller, allowing a low-privileged principal to request operations that should require elevated rights. See the Oracle Security Alert July 2026 for vendor-supplied details.

Attack Vector

Exploitation requires network access to the Agent Next Gen HTTPS endpoint and valid low-privileged credentials. The attacker issues crafted requests that exercise the missing access control checks. No user interaction is required. Successful requests yield unauthorized read and write access to data managed by Oracle Enterprise Manager Base Platform, with downstream effects on managed targets due to the scope change.

No verified public proof-of-concept is available at this time. Refer to Oracle's advisory for authoritative technical details.

Detection Methods for CVE-2026-46993

Indicators of Compromise

  • Unexpected HTTPS requests to Agent Next Gen endpoints originating from accounts that do not normally administer Oracle Enterprise Manager.
  • Unauthorized modifications to Enterprise Manager configuration, jobs, targets, or credentials outside of change windows.
  • Anomalous data extraction volumes from Enterprise Manager repository databases.
  • Authentication events for low-privileged Enterprise Manager users followed by privileged administrative operations.

Detection Strategies

  • Baseline Agent Next Gen HTTPS request patterns per user role and alert on deviations such as privileged verbs invoked by low-privileged roles.
  • Correlate Enterprise Manager audit logs with target-side database and middleware audit trails to identify actions initiated outside authorized workflows.
  • Monitor for creation or modification of Enterprise Manager named credentials, preferred credentials, and monitoring templates by non-administrative accounts.

Monitoring Recommendations

  • Forward Oracle Enterprise Manager audit logs, agent logs, and repository database audit records to a centralized analytics platform such as Singularity Data Lake for OCSF-normalized correlation.
  • Alert on any successful HTTPS authentication to Agent Next Gen from network segments not designated for Enterprise Manager administration.
  • Track privileged Enterprise Manager operations by role and generate weekly review reports for the platform owners.

How to Mitigate CVE-2026-46993

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update to Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 as directed in the vendor advisory.
  • Inventory all Agent Next Gen deployments and confirm patch status across every management server and monitored target.
  • Rotate Enterprise Manager credentials, including named and preferred credentials used to reach managed targets, after patching.
  • Restrict network access to the Enterprise Manager agent HTTPS ports to trusted administrative segments only.

Patch Information

Oracle addressed CVE-2026-46993 in the Oracle Security Alert July 2026. Administrators should download the applicable patch for Oracle Enterprise Manager Base Platform 13.5 or 24.1 from My Oracle Support and apply it during the next available maintenance window. Verify successful patch application through the OPatch inventory before returning agents to production.

Workarounds

  • No vendor-supplied workaround eliminates the vulnerability. Patching is the required remediation.
  • Reduce exposure by placing Enterprise Manager management servers and agents behind network segmentation that permits only authorized administrator sources.
  • Enforce least privilege by auditing Enterprise Manager roles and removing unnecessary low-privilege accounts that could be leveraged for exploitation.
bash
# Verify OPatch inventory after applying the July 2026 CPU
$ORACLE_HOME/OPatch/opatch lsinventory | grep -i "July 2026"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.