Executive brief
Oracle Business Intelligence Enterprise Edition is a data analytics and reporting platform used to manage enterprise analytics infrastructure. A local privilege escalation vulnerability allows a low-privileged attacker with logon access to compromise the system, potentially leading to complete takeover of the analytics server and access to all data, reports, and configurations managed by it.
Technical details
This is a local privilege escalation vulnerability in the Analytics Server component of Oracle Business Intelligence Enterprise Edition affecting versions 8.2.0.0.0 and 26.01.0.0.0. The vulnerability requires an attacker to already have low-privilege logon access to the infrastructure where the product runs. Successful exploitation grants the attacker full control over the Oracle Business Intelligence Enterprise Edition system, potentially leading to unauthorized access to sensitive analytics data, manipulation of reports and dashboards, and disruption of business intelligence operations. The vulnerability is easily exploitable with low complexity once access is obtained. Patch information and detailed remediation steps should be obtained from Oracle's security advisory.
Affected products
- Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed