SB2026091481 - Multiple vulnerabilities in Enterprise Manager Base Platform
Published: September 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 15 vulnerabilities.
1) Improper input validation (CVE-ID: CVE-2026-46868)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Extensibility Framework component in Oracle Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to execute arbitrary code.
2) Improper input validation (CVE-ID: CVE-2026-46867)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Extensibility Framework component in Oracle Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to execute arbitrary code.
3) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-34481)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause downstream log processing systems to reject or fail to index affected records.
The vulnerability exists due to improper serialization of non-finite floating-point values in JsonTemplateLayout when processing log events containing a MapMessage with an attacker-controlled floating-point value. A remote attacker can supply a non-finite floating-point value to cause downstream log processing systems to reject or fail to index affected records.
Exploitation is possible only if the application uses JsonTemplateLayout and logs a MapMessage containing the attacker-controlled value.
4) Improper input validation (CVE-ID: CVE-2026-46865)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Extensibility Framework component in Oracle Enterprise Manager Base Platform. A local privileged user can exploit this vulnerability to execute arbitrary code.
5) Improper input validation (CVE-ID: CVE-2026-46866)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote non-authenticated attacker to damange or delete data.
The vulnerability exists due to improper input validation within the Agent Next Gen component in Oracle Enterprise Manager Base Platform. A remote non-authenticated attacker can exploit this vulnerability to damange or delete data.
6) Improper input validation (CVE-ID: CVE-2026-46864)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote authenticated user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Agent Next Gen component in Oracle Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to execute arbitrary code.
7) Improper input validation (CVE-ID: CVE-2026-46872)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Install component in Oracle Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to execute arbitrary code.
8) Improper input validation (CVE-ID: CVE-2026-46875)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Deployment Library component in Oracle Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to execute arbitrary code.
9) Improper input validation (CVE-ID: CVE-2026-46856)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Metadata Plugin component in Oracle Enterprise Manager Base Platform. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
10) Improper input validation (CVE-ID: CVE-2026-46853)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Metadata Plugin component in Oracle Enterprise Manager Base Platform. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
11) Improper input validation (CVE-ID: CVE-2026-46857)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Oracle Management Service component in Oracle Enterprise Manager Base Platform. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
12) Improper input validation (CVE-ID: CVE-2026-46855)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote authenticated user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Metadata Plugin component in Oracle Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to execute arbitrary code.
13) Improper input validation (CVE-ID: CVE-2026-46852)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote authenticated user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Metadata Plugin component in Oracle Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to execute arbitrary code.
14) Improper input validation (CVE-ID: CVE-2026-46832)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote authenticated user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Discovery Framework component in Oracle Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to execute arbitrary code.
15) Improper input validation (CVE-ID: CVE-2026-46854)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote authenticated user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Target Management component in Oracle Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to execute arbitrary code.
Remediation
Install update from vendor's website.