Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation & Takeover
Action: Patch Immediately
AI Analysis

Impact

The vulnerability lies in the Platform Security component of Oracle Business Intelligence Enterprise Edition. An attacker who obtains high‑privilege credentials and can reach the platform over HTTP may exploit the flaw, enabling a complete compromise of the BI platform. The impact includes loss of confidentiality, integrity, and availability, effectively allowing the attacker to take full control of the system. This flaw is classified as a privilege escalation and broken access control weakness.

Affected Systems

Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0 is affected. No other products or versions are currently identified.

Risk and Exploitability

The CVSS v3.1 base score of 7.2 indicates high severity with significant impacts on confidentiality, integrity and availability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not yet listed in the CISA KEV catalog. However, because the attacker must have high‑privilege credentials and network reachability over HTTP, the risk remains significant, and the potential for a full platform takeover warrants prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 08:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch released for version 26.01.0.0.0 or upgrade to a later version that incorporates the fix as detailed in the Oracle advisory at https://www.oracle.com/security-alerts/cspusep2026.html
  • Restrict HTTP access via firewall rules so that only trusted internal hosts can reach the BI platform, thereby reducing the attack surface
  • Enforce least‑privilege policies on BI accounts and secure or disable high‑privilege credentials to limit the impact if the vulnerability is exploited
  • Enable comprehensive logging and anomaly detection for BI platform access to quickly detect any exploitation attempts

Generated by OpenCVE AI on September 20, 2026 at 08:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Exploit Allows Full Takeover of Oracle BI Enterprise Edition

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle BI Enterprise Edition Platform Security Vulnerability Enables Remote Takeover
Weaknesses CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title Oracle BI Enterprise Edition Platform Security Vulnerability Enables Remote Takeover
Weaknesses CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:38.708Z

Reserved: 2026-08-31T15:40:57.350Z

Link: CVE-2026-83273

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:42.706Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:39.763

Modified: 2026-09-17T14:17:39.003

Link: CVE-2026-83273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:30:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management