Summary
CVE-2026-70684 is a high-severity vulnerability in the Agent Next Gen component of Oracle Enterprise Manager Base Platform. It allows an unauthenticated, remote attacker with network access via HTTP to compromise the platform, potentially resulting in complete takeover of the affected system. Oracle rates the flaw 8.1 (High) on the CVSS v3.1 scale and characterizes it as difficult to exploit, but successful exploitation results in a full loss of confidentiality, integrity, and availability.
Technical details
- Root cause: A flaw in the Agent Next Gen component of Oracle Enterprise Manager Base Platform that can be abused to compromise the platform.
- Trigger conditions: Oracle describes the issue as "difficult to exploit," indicating specific, non-trivial conditions must be met by an attacker to successfully weaponize the flaw; no authentication or user interaction is required to attempt exploitation.
- Attack vector: Network-based, reachable via HTTP; no privileges and no user interaction are required (PR:N/UI:N), though attack complexity is rated High (AC:H).
- Impact: Successful exploitation can lead to complete compromise (takeover) of Oracle Enterprise Manager Base Platform, with high impact to confidentiality, integrity, and availability (C:H/I:H/A:H).
Affected software
- Oracle Enterprise Manager Base Platform, version 13.5 (Agent Next Gen component)
- Oracle Enterprise Manager Base Platform, version 24.1 (Agent Next Gen component)
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fixes provided by Oracle for Enterprise Manager Base Platform versions 13.5 and 24.1 as published in Oracle’s August 2026 Critical Patch Update / Security Alert. Organizations should identify all Oracle Enterprise Manager deployments (particularly the Agent Next Gen component) and apply the relevant patch as soon as possible given the network-exploitable, unauthenticated nature of the flaw.
- If immediate patching is not possible: Restrict network access to Oracle Enterprise Manager management interfaces and Agent Next Gen endpoints to trusted management networks only, and monitor HTTP traffic to these components for anomalous or exploitation-related activity until the patch can be applied.

