Description
Vulnerability in Oracle Essbase (component: Calculator). The supported version that is affected is 21.8.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks of this vulnerability can result in takeover of Oracle Essbase. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Calculator component of Oracle Essbase 21.8.1.0.0 that allows an attacker with low privileges and network access via HTTP to exploit the system. Successful use of the flaw can lead to full takeover of the Essbase instance, resulting in loss of confidentiality, integrity, and availability. The CVSS 3.1 base score of 8.8 highlights a high‑severity threat with an attack vector of network, low attack complexity, low privilege required, no user interaction, and common impact to all systems.

Affected Systems

This issue affects Oracle Corporation’s Essbase product, specifically version 21.8.1.0.0. No other versions or products are listed as impacted.

Risk and Exploitability

With an AV:N vector and low privilege requirements, an adversary can readily launch an attack from any network connection to the HTTP interface. The absence of a mitigation in the CISA KEV catalog does not diminish the potential danger, as the CVSS score indicates a high likelihood of major damage. While no EPSS data is available, the straightforward nature of the exploitation path suggests that the vulnerability could be leveraged by malicious actors once the product is detected in a networked environment.

Generated by OpenCVE AI on August 19, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy Oracle's security patch or upgrade to a version of Essbase that is not affected by this vulnerability.
  • Restrict or block external HTTP access to the Essbase Calculator service until a fix is applied.
  • Disable or remove the Calculator component from the Essbase installation if it is not required for business functions.

Generated by OpenCVE AI on August 19, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Oracle Essbase 21.8.1.0.0 Remote Takeover via Calculator Component
Weaknesses CWE-94

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Essbase (component: Calculator). The supported version that is affected is 21.8.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks of this vulnerability can result in takeover of Oracle Essbase. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle essbase
CPEs cpe:2.3:a:oracle:essbase:21.8.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle essbase
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:01:01.341Z

Reserved: 2026-08-04T22:06:34.589Z

Link: CVE-2026-70688

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:20.763

Modified: 2026-08-18T21:17:20.763

Link: CVE-2026-70688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T01:30:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')