Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the BI Platform Security component of Oracle Business Intelligence Enterprise Edition, allowing a low‑privileged attacker with network access via HTTP to bypass standard authentication controls. Successful exploitation enables creation, deletion, or modification of access rights to critical data, effectively granting the attacker unauthorized entry to all data managed by the platform. The vulnerability falls under CWE‑284, reflecting a broken access control weakness, and is rated with a CVSS 3.1 base score of 8.2, indicating high severity with significant confidentiality and integrity impacts.

Affected Systems

Oracle Corporation’s Oracle Business Intelligence Enterprise Edition (Oracle Analytics) is affected. The problematic releases are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The description notes a potential scope change that could also impact additional products if the BI platform is compromised, but no other specific product versions are listed.

Risk and Exploitability

The high CVSS score of 8.2 indicates a severe threat to confidentiality and integrity, yet the EPSS score of <1% shows low but nonzero exploitation probability. The vulnerability is not catalogued in the CISA KEV list, implying no known active exploits. The likely attack vector is network‑based HTTP targeting the BI platform, which only requires low‑privileged credentials. Because the affected instance is exposed to a network, organizations must weigh the low exploitation likelihood against the significant damage potential that a successful breach could inflict.

Generated by OpenCVE AI on August 20, 2026 at 18:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a version that includes the fix for CVE‑2026‑71096.
  • Restrict external network access to the BI platform by configuring firewall rules or VPN restrictions so that only trusted hosts can reach its HTTP interfaces.
  • Enforce strict role‑based access controls, trim user permissions to the least privilege necessary, and audit access logs regularly to detect unauthorized activity.

Generated by OpenCVE AI on August 20, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Business Intelligence Enterprise Edition
Vendors & Products Oracle Corporation
Oracle Corporation oracle Business Intelligence Enterprise Edition

Thu, 20 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Modification via Broken Access Control in Oracle Business Intelligence

Thu, 20 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Access Enables Unauthorized Data Access in Oracle Business Intelligence Enterprise Edition

Thu, 20 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Access Enables Unauthorized Data Access in Oracle Business Intelligence Enterprise Edition

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Modification via Low Privilege HTTP Attack in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284

Wed, 19 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Modification via Low Privilege HTTP Attack in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Business Intelligence
Oracle Corporation Oracle Business Intelligence Enterprise Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:01:55.600Z

Reserved: 2026-08-04T22:06:34.617Z

Link: CVE-2026-71096

cve-icon Vulnrichment

Updated: 2026-08-19T15:02:39.368Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:09.800

Modified: 2026-08-24T17:08:37.303

Link: CVE-2026-71096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:31:56Z

Weaknesses