Executive brief
Oracle Business Intelligence Enterprise Edition is a reporting and analytics platform used by enterprises to analyze business data and make decisions. A vulnerability in the platform's security component allows an unauthenticated attacker to gain complete control over the system through the network, potentially exposing or altering sensitive business intelligence data and reports. This could result in data theft, manipulation of analytics, or service disruption.
Technical details
This is an authentication bypass or unauthorized access vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition, exploitable remotely over HTTP without requiring user credentials. The vulnerability is difficult to exploit but allows an unauthenticated network attacker to achieve complete system compromise with high impact on confidentiality, integrity, and availability. Affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Oracle has released a security patch as part of their September 2026 critical patch update. No active exploitation in the wild has been reported at time of publication.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed: Vulnerability disclosed in Oracle's Critical Patch Update