Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local compromise via unauthenticated access to the underlying infrastructure
Action: Patch and Harden
AI Analysis

Impact

This vulnerability is located in the Platform Security component of Oracle Business Intelligence Enterprise Edition. An unauthenticated attacker that has logged on to the same infrastructure where the BI service runs can exploit it. The flaw allows the attacker to take over the BI system, resulting in full confidentiality, integrity, and availability compromise of the application. The vulnerability requires human interaction from a person other than the attacker, implying that an insider or a co‑operator must provide some user‑mode input or consent for the exploit to succeed. The impact is total loss of control over the affected BI instance.

Affected Systems

Affected releases are Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. These versions correspond to the product releases identified by the provided CPE strings. Administrators should verify that their installations match any of these version identifiers to determine exposure.

Risk and Exploitability

The CVSS 3.1 base score is 7.8, reflecting high confidentiality, integrity, and availability impact with local attack, low required privileges, and required user interaction. The EPSS score is less than 1 %, indicating a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires an unauthenticated attacker who has logged on to the infrastructure where the BI service runs and must convince a user to perform a required action. If achieved, the attacker gains full control of the BI instance.

Generated by OpenCVE AI on September 18, 2026 at 15:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any Oracle patch or upgrade to a version where the Platform Security issue is fixed
  • Reconfigure the BI platform to enforce strict authentication and disable any remaining unauthenticated access points
  • Isolate the BI servers within a dedicated network segment and restrict inbound traffic to trusted management hosts only

Generated by OpenCVE AI on September 18, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Infrastructure Access Compromises Oracle BI Enterprise Edition

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Infrastructure Access Compromises Oracle BI Enterprise Edition
Weaknesses CWE-284
CWE-287
CWE-640

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:37.941Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83294

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:26.283Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:42.193

Modified: 2026-09-17T14:17:40.017

Link: CVE-2026-83294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T16:00:09Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password