Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).
Published: 2026-07-21
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Business Intelligence Enterprise Edition contains a remote, unauthenticated flaw in the BI Platform Security component that allows an attacker to send crafted HTTP requests. Successful exploitation can cause the application to hang or crash, resulting in a complete denial of service. The same flaw also permits the attacker to insert, update, delete, or read data exposed by the BI service, thereby compromising confidentiality and integrity. The weakness is rooted in improperly controlled access and missing authentication, reflected by CWE‑284 and CWE‑306.

Affected Systems

The vulnerability affects Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0 and 26.01.0.0.0, the builds listed as impacted by Oracle.

Risk and Exploitability

With a CVSS 3.1 base score of 8.6, the issue is high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, yet the attack is considered easily exploitable and requires only network access via HTTP. An unauthenticated attacker can reach the vulnerable component from any network location that can reach the BI server, making the threat both remote and widely reachable.

Generated by OpenCVE AI on August 4, 2026 at 03:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security advisories for available patches for Oracle Business Intelligence Enterprise Edition and apply any issued updates.
  • Restrict HTTP traffic to the BI server by configuring firewalls or access control lists to allow only trusted IP addresses or internal tenants.
  • Continuously monitor the BI server’s logs for unusual HTTP requests or unauthorized data access attempts and investigate promptly.

Generated by OpenCVE AI on August 4, 2026 at 03:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-Based Remote Denial of Service and Data Breach in Oracle Business Intelligence Enterprise Edition

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-Based Remote Denial of Service and Data Breach in Oracle Business Intelligence Enterprise Edition

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:17:09.191Z

Reserved: 2026-07-08T15:51:55.576Z

Link: CVE-2026-60671

cve-icon Vulnrichment

Updated: 2026-07-24T19:17:03.854Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:08.093

Modified: 2026-08-07T21:22:42.117

Link: CVE-2026-60671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function