Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification, unauthorized data access, and partial denial of service
Action: Apply Patch
AI Analysis

Impact

The flaw is an access control bypass in the BI Search component of Oracle Business Intelligence Enterprise Edition. It allows an attacker with low privileges and basic HTTP network access to create, delete, or modify data, to read all data exposed by the system, and to trigger a partial denial of service. The weakness is a classic access‑control failure (CWE‑284) that results in full compromise of confidentiality, integrity, and some availability of the BI system.

Affected Systems

Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0, delivered by Oracle Corporation as part of the Enterprise Analytics suite, is affected. The vulnerability resides in the BI Search module of this product.

Risk and Exploitability

The CVSS base score of 8.3 highlights significant severity. The EPSS score is below 1%, suggesting that widespread exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by sending HTTP requests to the BI Search endpoint without user interaction; only a low level of privilege is required to trigger the access‑control bypass, making it reachable by many users in the network.

Generated by OpenCVE AI on September 18, 2026 at 19:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 as advised in the Oracle security alert.
  • Restrict HTTP access to the BI Search endpoint to trusted IP ranges or through network segmentation to narrow the attack surface.
  • Enforce strict role‑based and least‑privilege access controls in the BI Search configuration to prevent accidental or malicious data manipulation.
  • Configure monitoring and alerting on BI Search logs for unusual or unauthorized operations.

Generated by OpenCVE AI on September 18, 2026 at 19:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in Oracle BI Enterprise Edition BI Search (120)

Thu, 17 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in Oracle BI Enterprise Edition BI Search (120)
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:49.640Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83285

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:41.153

Modified: 2026-09-18T19:16:53.033

Link: CVE-2026-83285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:15:11Z

Weaknesses