Executive brief
Oracle Business Intelligence Enterprise Edition is a data analytics platform used to create reports and dashboards for business decision-making. An unauthenticated attacker with network access can exploit a vulnerability in the Analytics Web General component to gain unauthorized access to sensitive data, modify or delete critical information, and cause service interruptions. This vulnerability could compromise the confidentiality and integrity of all analytics data accessible through the platform.
Technical details
This is a difficult-to-exploit vulnerability in Oracle Business Intelligence Enterprise Edition's Analytics Web General component that allows unauthenticated network-based attackers to bypass security controls via HTTP. The vulnerability affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, and has a scope change meaning impacts extend beyond the directly affected component. Successful exploitation results in unauthorized creation, deletion, and modification of critical data; complete unauthorized access to all accessible Business Intelligence data; and partial denial of service. The CVSS 3.1 score is 8.9 (High), with a vector of AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L, indicating network accessibility but high attack complexity. No patch availability information is currently available.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed