Executive brief
Oracle Business Intelligence Enterprise Edition is a data analytics platform used to create reports and dashboards from corporate data. A low-privileged attacker with network access can exploit a security flaw in the BI Platform Security component to modify, delete, or access sensitive business data. The vulnerability can also impact other Oracle products that integrate with or depend on this analytics system.
Technical details
This is a difficult-to-exploit vulnerability in the BI Platform Security component of Oracle Business Intelligence Enterprise Edition that allows a low-privileged attacker with network access via HTTP to escalate privileges and gain unauthorized access to critical data. The vulnerability exhibits scope change, meaning compromise of OBIE can impact other connected Oracle products. Successful exploitation results in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of OBIE accessible data. The vulnerability affects versions 8.2.0.0.0 and 26.01.0.0.0, with a CVSS score of 7.1 indicating high severity with integrity and confidentiality impacts. A patch is expected from Oracle's security team.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed