ZeroHour

CVE-2026-83068

moderate

High-impact data disclosure in Oracle Enterprise Manager for Oracle Database 24.1

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83068 is a high-severity (CVSS 7.7) information disclosure vulnerability in the Core component of Oracle Enterprise Manager for Oracle Database, affecting version 24.1. A low-privileged attacker with network access to the OEM console over HTTP can exploit the flaw easily (low attack complexity, no user interaction) to read critical data, including complete access to all data reachable through Oracle Enterprise Manager for Oracle Database. Because the vulnerability exhibits a scope change, successful attacks can also significantly impact products beyond the OEM for Oracle Database boundary. The issue affects organizations running OEM 24.1 that expose the console to networks reachable by low-privilege or authenticated users. There is no evidence of exploitation in the wild and no public proof-of-concept at this time.

What to do: Apply the Oracle Critical Patch Update that remedies CVE-2026-83068 to your Oracle Enterprise Manager for Oracle Database 24.1 deployment as soon as it is available for your environment. Restrict network access to the OEM console (HTTP/HTTPS management ports) so only trusted admin subnets can reach it, and audit low-privileged OEM accounts for unusual data access. Because of the scope change, also review downstream Oracle Database and managed-target credentials accessible via OEM for signs of unauthorized reads.

Affected
Oracle Enterprise Manager for Oracle Database (component: Core)
Estimated exposure
moderate≈ low thousands of internet-exposed OEM consoles; overall enterprise deployments likely in the tens of thousands (estimate) — Oracle Enterprise Manager is deployed primarily inside large enterprise Oracle database estates, and public internet scans have historically shown only a few thousand exposed OEM consoles, so the truly internet-reachable footprint is small…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Core). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Oracle Database. While the vulnerability is in Oracle Enterprise Manager for Oracle Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager for Oracle Database accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.