Research & Development
$ #

CVE-2026-34279

Code execution in the Event Management component of the Oracle Enterprise Manager Base Platform

9.1 (Critical)

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Oracle Enterprise Manager Base Platform

13.5, 24.1

Jan Czerlunczakiewicz

Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform.

  • 12-11-2025 - Vulnerability reported to vendor
  • 21-04-2026 - Security advisory is published by the vendor