Executive brief
Oracle Business Intelligence Enterprise Edition is an analytics platform used by enterprises to process and visualize business data. A vulnerability in the installation component allows a low-privileged user with local system access to escalate privileges and take over the entire application, compromising confidentiality, integrity, and availability of analytics data and reports.
Technical details
This is a local privilege escalation vulnerability in the installation component of Oracle Business Intelligence Enterprise Edition. The vulnerability requires the attacker to have low-privilege logon access to the infrastructure where the application executes. With network access not required and minimal security controls bypassed (low complexity), a local attacker can achieve complete compromise of the application, including unauthorized access to data, modification of reports and configurations, and denial of service. The affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Patches or mitigations should be obtained from Oracle.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed