Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote takeover of Oracle Business Intelligence Enterprise Edition
Action: Immediate Patch
AI Analysis

Impact

A flaw within the Platform Security component of Oracle Business Intelligence Enterprise Edition permits a low‑privileged attacker with network reachability via HTTP to compromise the application. Successful exploitation can lead to complete takeover, exposing confidential data, altering integrity of analytics, and rendering the service unavailable.

Affected Systems

The vulnerability impacts Oracle Corporation’s Oracle Business Intelligence Enterprise Edition, specifically versions 8.2.0.0.0 and 26.01.0.0.0. These are the only releases confirmed to be affected by the flaw.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 illustrates a high risk to confidentiality, integrity, and availability, while the EPSS score of less than 1% indicates a low probability of active exploitation at present. The issue is not listed in the CISA KEV catalog, but the attack vector is a straightforward network HTTP approach that requires only a low‑privileged user account. Given the potential for complete application compromise, organizations should treat this as a high‑priority security issue and apply the vendor’s patch as soon as it becomes available.

Generated by OpenCVE AI on September 20, 2026 at 08:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Oracle Business Intelligence Enterprise Edition to a patched version that removes the Platform Security flaw.
  • Configure network firewalls and intrusion‑prevention systems to allow HTTP traffic to the BI server only from trusted IP ranges.
  • Enforce strict least‑privilege authentication and monitor account activity for unusual access patterns.

Generated by OpenCVE AI on September 20, 2026 at 08:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Platform Security Exploit Enables Low‑Privilege HTTP Attack to Compromise Oracle Business Intelligence Enterprise Edition

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Exploit Allows Full Takeover of Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Exploit Allows Full Takeover of Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:38.121Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83292

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:29.214Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:41.963

Modified: 2026-09-17T14:17:39.790

Link: CVE-2026-83292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management