Executive brief
Oracle Business Intelligence Enterprise Edition is an analytics and reporting platform used by enterprises to visualize and analyze business data. A vulnerability in the Analytics Server component allows a low-privileged attacker with network access to bypass authentication and gain administrative control over the entire system, potentially exposing sensitive business data and enabling malicious modifications to reports and analytics.
Technical details
This vulnerability in Oracle Business Intelligence Enterprise Edition's Analytics Server component is exploitable by a low-privileged network attacker without requiring user interaction. The attack vector is HTTP and can result in complete system compromise, granting the attacker confidentiality, integrity, and availability impacts. The vulnerability affects versions 8.2.0.0.0 and 26.01.0.0.0. The exact technical nature of the flaw is not disclosed in available references, but the high CVSS score and authentication bypass profile suggest it may involve privilege escalation or session handling flaws in the web interface.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed