Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the BI Search component of Oracle Business Intelligence Enterprise Edition and can be triggered by a low‑privileged attacker who has network access through HTTP. When exploited, the flaw permits the attacker to gain unauthorized access to critical data or even complete access to all data available in the BI Enterprise Edition environment. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) indicates that confidentiality is impacted while integrity and availability remain unaffected, reflecting the nature of an access‑control weakness that can expose sensitive information.

Affected Systems

Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected. These applications provide advanced analytics and reporting, and the impact may extend to other Oracle products through a scope change.

Risk and Exploitability

With a CVSS base score of 7.7 the vulnerability is considered high severity. The EPSS score is less than 1%, indicating a very low but nonzero chance of exploitation in the wild. The lack of a KEV listing does not reduce the risk, as the flaw permits network‑based compromise by an attacker with minimal privileges. The likely attack path involves an HTTP request to the BI Search endpoint, exploiting the improper access control to read data. The potential for data exposure across the system makes the threat significant even if the vulnerability is not currently exploited in the wild.

Generated by OpenCVE AI on August 20, 2026 at 19:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest patch or upgrade Oracle Business Intelligence Enterprise Edition to a version that contains the fix for BI Search as announced in Oracle's security advisory
  • Restrict HTTP access to the BI Enterprise Edition servers to a limited set of trusted hosts using firewall rules or network segmentation
  • Configure stricter authentication and authorization controls for BI Search endpoints to ensure that only properly privileged users can access sensitive data

Generated by OpenCVE AI on August 20, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Business Intelligence Enterprise Edition
Vendors & Products Oracle Corporation
Oracle Corporation oracle Business Intelligence Enterprise Edition

Thu, 20 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Oracle BI Search

Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Access Enables Unauthorized Data Access in Oracle BI Enterprise Edition
Weaknesses CWE-200

Wed, 19 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Access Enables Unauthorized Data Access in Oracle BI Enterprise Edition
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Business Intelligence
Oracle Corporation Oracle Business Intelligence Enterprise Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:04:29.619Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:05.400

Modified: 2026-08-24T15:52:47.460

Link: CVE-2026-71056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:32:07Z

Weaknesses