Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Machine Learning). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Full System Compromise
Action: Patch Immediately
AI Analysis

Impact

A local vulnerability in the Oracle Business Intelligence Enterprise Edition machine learning component allows an attacker with low privileges who can log on to the underlying infrastructure to gain full control of the BI system, compromising confidentiality, integrity, and availability. The flaw is exploitable in versions 8.2.0.0.0 and 26.01.0.0.0, enabling a takeover of the application.

Affected Systems

Oracle Corporation’s Business Intelligence Enterprise Edition, versions 8.2.0.0.0 and 26.01.0.0.0, are affected. This includes the machine learning component of Oracle Analytics running in enterprise deployments.

Risk and Exploitability

The CVSS v3.1 score of 7.8 and AV:L, AC:L, PR:L, UI:N vector indicate a high‑severity local privilege attack that requires only low privilege. The EPSS score of < 1% suggests that widespread exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, once exploited it gives the attacker full control over the BI environment and can be used to exfiltrate sensitive data, disrupt services, or pivot to other systems on the network. The attack scenario likely involves the attacker logging into a host that runs the BI service, using the vulnerability to bypass normal authorization checks and take over the application.

Generated by OpenCVE AI on September 17, 2026 at 03:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or update to a newer non‑affected version of Business Intelligence Enterprise Edition for both 8.2.0.0.0 and 26.01.0.0.0.
  • Restrict local logon rights to only users who truly need access to the BI server and enforce least‑privilege principles.
  • Segregate the BI server behind a firewall or in a separate network zone, limiting exposure to untrusted hosts.
  • Monitor authentication events for anomalous activity and conduct regular audits of BI user privileges.

Generated by OpenCVE AI on September 17, 2026 at 03:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Business Intelligence Enterprise Edition
Vendors & Products Oracle Corporation
Oracle Corporation oracle Business Intelligence Enterprise Edition

Thu, 17 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Low‑privilege takeover of Oracle Business Intelligence Enterprise Edition via Machine Learning component
Weaknesses CWE-269
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Machine Learning). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
Oracle Corporation Oracle Business Intelligence Enterprise Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:12.969Z

Reserved: 2026-08-31T15:40:57.337Z

Link: CVE-2026-83071

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:16.000

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T08:15:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-285

    Improper Authorization