Executive brief
Oracle Business Intelligence Enterprise Edition is a data analytics platform used by organizations to create reports and dashboards from business data. A vulnerability in the BI Search component allows a low-privileged user with local access to the system to gain complete control of the Analytics application, potentially compromising sensitive business intelligence data and reports.
Technical details
The vulnerability exists in the BI Search component of Oracle Business Intelligence Enterprise Edition and is exploitable by a low-privileged attacker with logon access to the infrastructure. The vulnerability allows privilege escalation to take over the entire Oracle Business Intelligence Enterprise Edition system. No authentication to the application itself is required—only local infrastructure access—and exploitation is straightforward (CVSS Access Complexity: Low). Successful exploitation results in complete compromise of confidentiality, integrity, and availability of the Analytics system.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed: Oracle published advisory