Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local, low‑privilege attacker who can log on to the infrastructure where Oracle Business Intelligence Enterprise Edition runs can exploit a flaw in the Platform Security component. The vulnerability allows the attacker to fully compromise the BI installation, gaining confidentiality, integrity, and availability damage as indicated by the CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The flaw is a CWE-284 vulnerability, indicating an Improper Access Control weakness. The impact extends to all data accessed through the BI service and to any integrated applications.

Affected Systems

Oracle Corporation’s Oracle Business Intelligence Enterprise Edition, version 26.01.0.0.0, is affected. No other versions or products are listed as vulnerable.

Risk and Exploitability

The CVSS base score of 7.8 classifies this flaw as high severity. The EPSS score of < 1% indicates a low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it may not be widely exploited yet. However, because the attack vector is local and requires only low privileges, an attacker who has any foothold on the host can potentially gain full control of the BI server. Management and auditing controls should consider the possibility of collateral damage to other services on the host.

Generated by OpenCVE AI on August 20, 2026 at 19:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch identified in Oracle’s Security Alert Aug 2026 (CSPU AUG 2026) to address CVE‑2026‑71097.
  • Restrict local access to the Oracle Business Intelligence Enterprise Edition services, ensuring that only accounts with necessary privileges can log in to the underlying infrastructure.
  • Review and enforce least‑privilege permissions for directories and binaries associated with the Platform Security component, following Oracle’s configuration guidelines.

Generated by OpenCVE AI on August 20, 2026 at 19:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Business Intelligence Enterprise Edition
Vendors & Products Oracle Corporation
Oracle Corporation oracle Business Intelligence Enterprise Edition

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Business Intelligence Enterprise Edition Platform Security

Thu, 20 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Business Intelligence Enterprise Edition Platform Security

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Local Logon Exploitation Allows Full Compromise of Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-732

Wed, 19 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Local Logon Exploitation Allows Full Compromise of Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
Oracle Corporation Oracle Business Intelligence Enterprise Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:01:49.735Z

Reserved: 2026-08-04T22:06:34.617Z

Link: CVE-2026-71097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:09.917

Modified: 2026-08-24T17:08:43.920

Link: CVE-2026-71097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:31:55Z

Weaknesses