Executive brief
Oracle Business Intelligence Enterprise Edition is a data analytics and reporting platform used by enterprises to analyze business data. A network-accessible vulnerability in its SOAP interface allows low-privileged users to gain complete control over the analytics system, potentially exposing sensitive business data and disrupting reporting operations critical to decision-making.
Technical details
A difficult-to-exploit privilege escalation vulnerability exists in the Analytics Web General component of Oracle Business Intelligence Enterprise Edition, exploitable via SOAP protocol. The vulnerability requires network access and a valid low-privileged account but no user interaction. Successful exploitation allows an attacker to achieve complete system takeover with full confidentiality, integrity, and availability impacts. Affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0; patch availability and details have not yet been disclosed.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed