Executive brief
A security vulnerability has been identified in Oracle Business Intelligence Enterprise Edition, a platform used by organizations for data analysis and reporting. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft of critical information or the unauthorized modification and deletion of records within the system.
Technical details
This vulnerability exists within the BI Platform Security component of Oracle Business Intelligence Enterprise Edition. It is classified as an easily exploitable flaw that requires no user interaction or prior authentication (PR:N/UI:N). An attacker can exploit this over the network via HTTP to gain high-impact confidentiality access (C:H) and low-impact integrity access (I:L). This allows for the unauthorized viewing of all accessible data and the ability to perform unauthorized updates, inserts, or deletes on a subset of that data. Affected versions include 8.2.0.0.0 and 26.01.0.0.0.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0
Timeline
- 2026-07-21: disclosed: Initial publication of the CVE record.
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update.