Impact
An unauthenticated vulnerability in the BI Platform Security component of Oracle Business Intelligence Enterprise Edition allows an attacker who can reach the service over HTTP to obtain full read access to all data exposed by the platform. The flaw is an improper access control weakness (CWE‑284) and was rated with a CVSS v3.1 base score of 7.5, indicating a high severity impact on confidentiality.
Affected Systems
Affected products are Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0 and 26.01.0.0.0, as identified by Oracle in their August 2026 security alert.
Risk and Exploitability
The EPSS score of < 1% suggests a very low probability of exploitation under current publicly available exploits, and the vulnerability is not listed in the CISA KEV catalog. No publicly documented exploits exist to date, which is inferred from the available information. The flaw is network‑based over plain HTTP and requires no credentials, so any environment that exposes the BI Platform is a potential target. The overall risk profile combines a high severity confidentiality impact with a low likelihood of exploitation, but the presence of the issue warrants prompt remediation.
OpenCVE Enrichment