Executive brief
Oracle Business Intelligence Enterprise Edition is an analytics platform used by enterprises to process and analyze business data. A local privilege escalation vulnerability in the Platform Security component allows an attacker with infrastructure access to compromise the system through social engineering, potentially gaining full control over the analytics platform and the sensitive business data it contains.
Technical details
This is a local privilege escalation vulnerability in the Oracle Business Intelligence Enterprise Edition Platform Security component, affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability requires the attacker to have logon access to the infrastructure where the product executes and requires user interaction (social engineering or tricking another user), but no prior authentication to the application itself. Successful exploitation allows an unauthenticated attacker to achieve complete compromise (confidentiality, integrity, and availability) of the Business Intelligence Enterprise Edition system. No patch availability information is currently disclosed in the advisory.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed