Executive brief
Oracle Business Intelligence Enterprise Edition is an enterprise analytics platform used to analyze and report on business data. An unauthenticated attacker can bypass authentication via a network-based vulnerability to gain full read access to all data stored in the system, exposing sensitive business intelligence and analytics information without requiring any valid credentials.
Technical details
This is an authentication bypass vulnerability in Oracle Business Intelligence Enterprise Edition's Analytics Server component, exploitable over HTTP via the network without requiring user interaction or authentication. The vulnerability allows an unauthenticated attacker with network access to gain unauthorized read access to all data within the system. Affected versions include 8.2.0.0.0 and 26.01.0.0.0. The vulnerability has a CVSS 3.1 score of 7.5 with high confidentiality impact. No patch information is currently available from the advisory text, though Oracle likely released fixes through their August 2026 Critical Patch Update.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0
Timeline
- 2026-08-18: disclosed
- 2026-08-18: advisory: Oracle Critical Patch Update published