CVE-2026-83355
moderateUnauthenticated HTTP Flaw in Oracle Enterprise Manager for Fusion Middleware Metrics Component Enables Full Takeover
CVE-2026-83355 is a critical (CVSS 9.8) vulnerability in the Metrics component of Oracle Enterprise Manager for Fusion Middleware, affecting supported releases 13.5 and 24.1. It is easily exploitable by an unauthenticated attacker who has network access to the affected system via HTTP, requiring no privileges and no user interaction. A successful attack can result in a complete takeover of Oracle Enterprise Manager for Fusion Middleware, with high impact on confidentiality, integrity, and availability. Because the product is a centralized management console, compromise could also expose credentials and configuration data for the middleware estates it manages. As of now, there is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83355 to all Oracle Enterprise Manager for Fusion Middleware 13.5 and 24.1 installations as a priority, given the unauthenticated, network-reachable nature of the flaw. In the interim, restrict HTTP access to the OEM console and Metrics endpoints to trusted management networks via firewall rules or a VPN, and verify the console is not exposed to the public internet. Review audit logs for unexplained administrative changes or new accounts that could indicate attempted compromise.
| Oracle Enterprise Manager for Fusion Middleware (Oracle Enterprise Manager, component: Metrics) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager for Fusion Middleware. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Fusion Middleware. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.