Executive brief
Oracle Business Intelligence Enterprise Edition is a data analytics and reporting platform used by organizations to analyze business data and generate reports. A vulnerability in its Presentation Services component allows an authenticated attacker with network access to achieve complete compromise of the system, potentially leading to unauthorized access, data manipulation, and service disruption.
Technical details
This vulnerability exists in the Presentation Services component of Oracle Business Intelligence Enterprise Edition and can be exploited via SOAP protocol by a low-privileged authenticated attacker with network access. The vulnerability is classified as difficult to exploit (CVSS access complexity: high), requiring authentication and specific conditions. Successful exploitation results in complete system compromise, including confidentiality, integrity, and availability impacts. Affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Patch information is not currently available from the provided advisory.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed: CVE-2026-83295 published