ZeroHour

CVE-2026-83355

moderate

Unauthenticated HTTP Flaw in Oracle Enterprise Manager for Fusion Middleware Metrics Component Enables Full Takeover

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83355 is a critical (CVSS 9.8) vulnerability in the Metrics component of Oracle Enterprise Manager for Fusion Middleware, affecting supported releases 13.5 and 24.1. It is easily exploitable by an unauthenticated attacker who has network access to the affected system via HTTP, requiring no privileges and no user interaction. A successful attack can result in a complete takeover of Oracle Enterprise Manager for Fusion Middleware, with high impact on confidentiality, integrity, and availability. Because the product is a centralized management console, compromise could also expose credentials and configuration data for the middleware estates it manages. As of now, there is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83355 to all Oracle Enterprise Manager for Fusion Middleware 13.5 and 24.1 installations as a priority, given the unauthenticated, network-reachable nature of the flaw. In the interim, restrict HTTP access to the OEM console and Metrics endpoints to trusted management networks via firewall rules or a VPN, and verify the console is not exposed to the public internet. Review audit logs for unexplained administrative changes or new accounts that could indicate attempted compromise.

Affected
Oracle Enterprise Manager for Fusion Middleware (Oracle Enterprise Manager, component: Metrics)
Estimated exposure
moderateThousands of installations globally (order of magnitude: low thousands of internet-exposed consoles, tens of thousands of total deployments) — Oracle Enterprise Manager is on-premises enterprise management software deployed by Oracle middleware customers worldwide; public internet scans historically show only a small fraction (low thousands) of OEM consoles exposed, with most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager for Fusion Middleware. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Fusion Middleware. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.