Impact
The vulnerability involves an improper access control flaw (CWE-284) in the Platform Security component of Oracle Business Intelligence Enterprise Edition. An attacker who has local low‑privileged access to the infrastructure on which the product runs can exploit this weakness, leading to a full compromise of the BI environment. The flaw results in loss of confidentiality, integrity, and availability, with a CVSS 3.1 base score of 7.0.
Affected Systems
Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0 is the only affected release. The vulnerability applies only to this product and version from Oracle Corporation.
Risk and Exploitability
The vulnerability is assessable locally (AV:L) and the attacker must possess low‑privileged credentials (PR:L). Exploitation can be performed without user interaction (UI:N). The CVSS score of 7.0 indicates a high risk. The EPSS score is < 1 % and the issue is not listed in the CISA KEV catalog, but the impact is severe if exploited. Attackers with sensitive system access can achieve full takeover of the BI platform.
OpenCVE Enrichment