Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation leading to full compromise of Oracle BI Enterprise Edition
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the Platform Security component of Oracle Business Intelligence Enterprise Edition, allowing a local attacker who can log on to the underlying infrastructure to compromise the product and result in a complete takeover, with full access to the system’s data, configuration and services availability.

Affected Systems

Affected systems include Oracle Corporation’s Oracle Business Intelligence Enterprise Edition, specifically versions 8.2.0.0.0 and 26.01.0.0.0, as identified in the CNA and CPE strings.

Risk and Exploitability

The CVSS base score of 7.8 indicates significant impact with high confidentiality, integrity and availability effects; the EPSS score of less than 1% suggests low current exploitation likelihood, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector requires local access (AV:L) with low complexity, low privilege, and no user interaction, indicating that low‑privileged users with logon rights can exploit the flaw, making it a high‑risk local privilege escalation that could enable full control of the Oracle BI instance if successful.

Generated by OpenCVE AI on September 18, 2026 at 18:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check Oracle's official advisory and apply the latest patch or update that addresses this privilege escalation in versions 8.2.0.0.0 and 26.01.0.0.0.
  • Limit local logon privileges on the infrastructure where Oracle BI Enterprise Edition runs, ensuring only authorized administrators can log in.
  • Apply OS‑level hardening and least‑privilege practices on isolating the Oracle BI instance in a separate network segment and enforce strict network segmentation to limit lateral movement from compromised hosts.

Generated by OpenCVE AI on September 18, 2026 at 18:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Full Compromise of Oracle Business Intelligence Enterprise Edition

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Full Compromise of Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-269

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:14.704Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83291

cve-icon Vulnrichment

Updated: 2026-09-17T12:50:30.715Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:41.843

Modified: 2026-09-17T14:17:39.680

Link: CVE-2026-83291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:45:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management