Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the BI Platform Security component of Oracle Business Intelligence Enterprise Edition, allowing an unauthenticated attacker reachable over HTTP to bypass existing security controls. Successful exploitation grants the attacker unauthorized read access to critical data and, in many cases, full access to all data exposed by the platform, plus the ability to create, modify or delete data entries. The impact is high confidentiality loss and moderate integrity compromise, resulting in potential data exfiltration and tampering.

Affected Systems

Oracle Business Intelligence Enterprise Edition, part of Oracle Analytics, is affected in the supported versions 8.2.0.0.0 and 26.01.0.0.0. Any installation of this enterprise edition that exposes the BI platform over HTTP is susceptible, regardless of environment or network location, as the issue hinges solely on HTTP access to the platform.

Risk and Exploitability

The CVSS 3.1 base score of 8.2 classifies this issue as high severity, while an EPSS score of less than 1% indicates a low current probability of exploitation. The vulnerability is absent from the CISA KEV catalog. Exploitation requires only network connectivity to an HTTP endpoint and no user credentials or privileged access, making the attack vector simple and straightforward.

Generated by OpenCVE AI on August 4, 2026 at 16:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that addresses CVE-2026-60674 to all affected Oracle Business Intelligence Enterprise Edition installations.
  • Restrict HTTP access to the BI platform by enforcing firewall rules, VPN or subnet segmentation so that only trusted networks can reach the HTTP endpoints.
  • Verify and tighten authentication, authorization, and role‑based access control settings on the BI platform to eliminate unauthenticated access to data and management interfaces.

Generated by OpenCVE AI on August 4, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Modification in Oracle BI Enterprise Edition
Weaknesses CWE-284
CWE-287

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Access and Modification in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-285

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Access and Modification in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-285

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Compromise in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-285

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Compromise in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:33:32.746Z

Reserved: 2026-07-08T15:51:55.577Z

Link: CVE-2026-60674

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:08.330

Modified: 2026-08-07T21:22:12.237

Link: CVE-2026-60674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function