Executive brief
Oracle Essbase is a financial planning and enterprise performance management solution used by organizations to consolidate, plan, and analyze business data. An unauthenticated attacker can remotely compromise the application via HTTP, potentially gaining full control of the system and accessing or modifying sensitive financial and operational data.
Technical details
This is an unauthenticated remote code execution vulnerability in Oracle Essbase's Infrastructure component affecting version 21.8.1.0.0. The vulnerability is easily exploitable via network-accessible HTTP requests and requires no user interaction or prior authentication. Successful exploitation allows an unauthenticated attacker to achieve full system compromise, including arbitrary code execution with impacts to confidentiality, integrity, and availability of the Essbase system and its data. The attack vector is network-based with low attack complexity. Oracle has released security guidance, though specific patch details are unavailable from the referenced sources.
Affected products
- Oracle Essbase 21.8.1.0.0
Timeline
- 2026-08-18: disclosed
- 2026-08-18: advisory