Executive brief
A vulnerability in Oracle's business analytics platform allows an unauthenticated attacker to remotely disrupt services or access sensitive data. An exploit could lead to a complete system shutdown (denial of service) or unauthorized viewing and modification of business intelligence data. This poses a significant risk to both operational availability and data integrity.
Technical details
This vulnerability exists in the BI Platform Security component of Oracle Business Intelligence Enterprise Edition. It is classified as easily exploitable, requiring no authentication or user interaction, and is reachable via the HTTP protocol. An attacker can exploit this flaw to cause a repeatable crash or hang of the application, resulting in a complete denial of service (DoS). Additionally, the vulnerability allows for unauthorized read access to a subset of data and unauthorized update, insert, or delete access to certain accessible data records. Affected versions include 8.2.0.0.0 and 26.01.0.0.0.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update