Executive brief
Oracle Business Intelligence Enterprise Edition is an analytics and reporting platform used by enterprises to analyze and visualize business data. This vulnerability allows a low-privileged user with local access to the server to gain full control of the application through social engineering (requiring another user's interaction). A successful attack could lead to complete compromise of the analytics system, affecting data confidentiality, integrity, and availability across the entire platform.
Technical details
This is a privilege escalation vulnerability in Oracle Business Intelligence Enterprise Edition (version 26.01.0.0.0) affecting the Platform Security component. The vulnerability requires local access to the infrastructure where the application runs, along with low-privilege credentials and user interaction from another person. The attack vector is local with high exploitation complexity, indicating that specific conditions or user actions are needed to exploit it successfully. A successful exploit results in complete takeover of the application with scope change, meaning the compromise can significantly impact other products in the same environment. Patch availability and specific technical remediation details were not accessible in the advisory materials.
Affected products
- Oracle Business Intelligence Enterprise Edition 26.01.0.0.0
Timeline
- 2026-09-15: disclosed