Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Business Intelligence Enterprise Edition allows an unauthenticated attacker who can reach the system over HTTP to access data that should be protected by authentication. The flaw effectively bypasses the authentication mechanism, enabling the attacker to read any data exposed by the BI instance, thereby compromising confidentiality and potentially exposing sensitive business information.

Affected Systems

The vulnerabilities affect Oracle Corporation’s Oracle Business Intelligence Enterprise Edition in the 8.2.0.0.0 and 26.01.0.0.0 releases. The flaw resides in the Analytics Server component of the product. Only these versions are known to be impacted.

Risk and Exploitability

Based on the description, it is inferred that the attack vector is over HTTP network access. The flaw has a CVSS 3.1 base score of 7.5, indicating high risk. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the issue over the network via a standard HTTP connection without any prior authentication. Given the simplicity of the attack path, the vulnerability is considered readily exploitable in environments where the BI server is exposed to the internet or an untrusted subnet.

Generated by OpenCVE AI on August 21, 2026 at 02:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses CVE‑2026‑71107 for the affected 8.2.0.0.0 and 26.01.0.0.0 releases.
  • Restrict HTTP access to the BI servers by moving them to a trusted network segment or enforcing strict firewall rules that block unauthenticated traffic from external sources.
  • Verify that anonymous and unauthenticated access options are disabled in the Analytics Server configuration and audit logs for any unauthorized access attempts.

Generated by OpenCVE AI on August 21, 2026 at 02:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Breach in Oracle Business Intelligence Enterprise Edition

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Compromise in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-287

Thu, 20 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Compromise in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-287

Wed, 19 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Disclosure via HTTP in Oracle BI Enterprise Edition
Weaknesses CWE-284
CWE-287

Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Disclosure via HTTP in Oracle BI Enterprise Edition
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T18:34:19.925Z

Reserved: 2026-08-04T22:06:34.617Z

Link: CVE-2026-71107

cve-icon Vulnrichment

Updated: 2026-08-20T18:10:54.735Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:11.060

Modified: 2026-08-24T15:50:39.393

Link: CVE-2026-71107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T03:00:04Z

Weaknesses