Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Compromise of Oracle Business Intelligence Enterprise Edition
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the BI Search component of Oracle Business Intelligence Enterprise Edition. An attacker with low privileged access to the machine that hosts the BI service can exploit this flaw to achieve local privilege escalation, ultimately compromising the entire application and leading to loss of confidentiality, integrity, and availability. The flaw is an improper access control and privilege management issue, reflected in CWE-269.

Affected Systems

Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected. The product is delivered by Oracle Corporation and is widely deployed in enterprise deployments that rely on the BI Search functionality.

Risk and Exploitability

CVSS v3.1 base score is 7.8, with a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicating that the vulnerability can be exploited locally by an attacker who has low privileges. The EPSS score is below 1%, suggesting a low probability of current exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw grants full control over the affected application, it warrants prioritized remediation.

Generated by OpenCVE AI on September 20, 2026 at 08:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and apply the latest official patch or upgrade Oracle Business Intelligence Enterprise Edition to a non‑affected version. This is the most effective remedy.
  • Limit local system access for non‑privileged users so they cannot authenticate to the BI service or execute commands that would reach the BI Search component. Implement strict role‑based access controls on the host.
  • As a temporary workaround, if feasible, disable the BI Search feature until a patch is applied, preventing the vulnerability from being actionable.
  • Review and enforce the vendor’s hardening guidelines, disabling unused services and tightening configuration files that govern the BI Search component.

Generated by OpenCVE AI on September 20, 2026 at 08:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Business Intelligence Enterprise Edition BI Search Component

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Exploitable Local Privilege Escalation in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284

Wed, 16 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Exploitable Local Privilege Escalation in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:15.017Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83288

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:41.487

Modified: 2026-09-17T14:17:39.340

Link: CVE-2026-83288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:30:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management