CVE-2026-83068
moderateHigh-impact data disclosure in Oracle Enterprise Manager for Oracle Database 24.1
CVE-2026-83068 is a high-severity (CVSS 7.7) information disclosure vulnerability in the Core component of Oracle Enterprise Manager for Oracle Database, affecting version 24.1. A low-privileged attacker with network access to the OEM console over HTTP can exploit the flaw easily (low attack complexity, no user interaction) to read critical data, including complete access to all data reachable through Oracle Enterprise Manager for Oracle Database. Because the vulnerability exhibits a scope change, successful attacks can also significantly impact products beyond the OEM for Oracle Database boundary. The issue affects organizations running OEM 24.1 that expose the console to networks reachable by low-privilege or authenticated users. There is no evidence of exploitation in the wild and no public proof-of-concept at this time.
What to do: Apply the Oracle Critical Patch Update that remedies CVE-2026-83068 to your Oracle Enterprise Manager for Oracle Database 24.1 deployment as soon as it is available for your environment. Restrict network access to the OEM console (HTTP/HTTPS management ports) so only trusted admin subnets can reach it, and audit low-privileged OEM accounts for unusual data access. Because of the scope change, also review downstream Oracle Database and managed-target credentials accessible via OEM for signs of unauthorized reads.
| Oracle Enterprise Manager for Oracle Database (component: Core) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Core). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Oracle Database. While the vulnerability is in Oracle Enterprise Manager for Oracle Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager for Oracle Database accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.