Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution / System Takeover
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Analytics Web General component of Oracle Business Intelligence Enterprise Edition. It permits a low-privileged attacker that can reach the SOAP interface over the network to bypass normal access controls and gain full control over the BI system. Successful exploitation would allow complete takeover of the application, compromising confidentiality, integrity, and availability of all underlying data and services. The weakness corresponds to Configuration or Permission Errors (CWE-269).

Affected Systems

Affected deployments include Oracle Business Intelligence Enterprise Edition from Oracle Corporation, specifically versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. All installations running these releases without the vendor’s patch remain vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates high severity. The EPSS score is less than 1 percent, suggesting that exploitation opportunities are currently low, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Nevertheless, the attack vector is straightforward: an attacker with network connectivity to the SOAP endpoint can submit a crafted request that bypasses normal access controls and grants them unrestricted authority over the BI system.

Generated by OpenCVE AI on September 20, 2026 at 08:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for Business Intelligence Enterprise Edition that addresses this vulnerability.
  • Restrict network access to the SOAP interface by limiting it to trusted IP ranges or applying firewall rules so that only authorized internal users can reach the SOAP service.
  • Enforce strong authentication and authorization checks on the Analytics Web General component to ensure that only privileged users can perform sensitive actions.
  • Monitor SOAP traffic for anomalous or unexpected requests that could indicate an exploitation attempt.

Generated by OpenCVE AI on September 20, 2026 at 08:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Oracle BI Enterprise Edition SOAP Access Bypass Enables System Takeover

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle Business Intelligence Enterprise Edition SOAP Access Control Flaw Leading to System Compromise
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Oracle Business Intelligence Enterprise Edition SOAP Access Control Flaw Leading to System Compromise
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:38.269Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83289

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:32.496Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:41.597

Modified: 2026-09-17T14:17:39.453

Link: CVE-2026-83289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management