SB2026091481 - Multiple vulnerabilities in Enterprise Manager Base Platform



SB2026091481 - Multiple vulnerabilities in Enterprise Manager Base Platform

Published: September 14, 2026

Security Bulletin ID SB2026091481
CSH Severity
High
Patch available
YES
Number of vulnerabilities 15
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 73% Medium 20% Low 7%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 15 vulnerabilities.


1) Improper input validation (CVE-ID: CVE-2026-46868)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote privileged user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Extensibility Framework component in Oracle Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to execute arbitrary code.


2) Improper input validation (CVE-ID: CVE-2026-46867)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote privileged user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Extensibility Framework component in Oracle Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to execute arbitrary code.


3) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-34481)

CWE-ID: CWE-116 - Improper Encoding or Escaping of Output

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause downstream log processing systems to reject or fail to index affected records.

The vulnerability exists due to improper serialization of non-finite floating-point values in JsonTemplateLayout when processing log events containing a MapMessage with an attacker-controlled floating-point value. A remote attacker can supply a non-finite floating-point value to cause downstream log processing systems to reject or fail to index affected records.

Exploitation is possible only if the application uses JsonTemplateLayout and logs a MapMessage containing the attacker-controlled value.


4) Improper input validation (CVE-ID: CVE-2026-46865)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Extensibility Framework component in Oracle Enterprise Manager Base Platform. A local privileged user can exploit this vulnerability to execute arbitrary code.


5) Improper input validation (CVE-ID: CVE-2026-46866)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote non-authenticated attacker to damange or delete data.

The vulnerability exists due to improper input validation within the Agent Next Gen component in Oracle Enterprise Manager Base Platform. A remote non-authenticated attacker can exploit this vulnerability to damange or delete data.


6) Improper input validation (CVE-ID: CVE-2026-46864)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote authenticated user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Agent Next Gen component in Oracle Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to execute arbitrary code.


7) Improper input validation (CVE-ID: CVE-2026-46872)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote privileged user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Install component in Oracle Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to execute arbitrary code.


8) Improper input validation (CVE-ID: CVE-2026-46875)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote privileged user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Deployment Library component in Oracle Enterprise Manager Base Platform. A remote privileged user can exploit this vulnerability to execute arbitrary code.


9) Improper input validation (CVE-ID: CVE-2026-46856)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Metadata Plugin component in Oracle Enterprise Manager Base Platform. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


10) Improper input validation (CVE-ID: CVE-2026-46853)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Metadata Plugin component in Oracle Enterprise Manager Base Platform. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


11) Improper input validation (CVE-ID: CVE-2026-46857)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Oracle Management Service component in Oracle Enterprise Manager Base Platform. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


12) Improper input validation (CVE-ID: CVE-2026-46855)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote authenticated user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Metadata Plugin component in Oracle Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to execute arbitrary code.


13) Improper input validation (CVE-ID: CVE-2026-46852)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote authenticated user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Metadata Plugin component in Oracle Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to execute arbitrary code.


14) Improper input validation (CVE-ID: CVE-2026-46832)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote authenticated user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Discovery Framework component in Oracle Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to execute arbitrary code.


15) Improper input validation (CVE-ID: CVE-2026-46854)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote authenticated user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Target Management component in Oracle Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to execute arbitrary code.


Remediation

Install update from vendor's website.