Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Vulnerability in Oracle Business Intelligence Enterprise Edition's Presentation Services component allows low‑privileged attackers with network access to exploit SOAP calls. Successful exploitation can lead to full takeover of the BI platform, compromising confidentiality, integrity, and availability, which aligns with the CVSS vector of AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. The bug involves improper privilege management, as indicated by CWE-269.

Affected Systems

Oracle Business Intelligence Enterprise Edition of Oracle Analytics, versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected. No sub‑version specificity beyond these main release numbers is reported.

Risk and Exploitability

CVSS 3.1 base score of 7.5 indicates high severity. EPSS score below 1% suggests limited exploitation probability. The vulnerability is not listed in CISA KEV. The open SOAP interface, combined with a low‑privilege requirement, suggests that internal actors with network access could target the endpoint. Based on how this vulnerability is described, it is inferred that an attacker first must discover an exposed SOAP endpoint and then submit a malicious payload, after which remote code execution could occur.

Generated by OpenCVE AI on September 20, 2026 at 08:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a non‑affected version.
  • Restrict network access to Presentation Services SOAP endpoints with firewall rules or IP whitelisting.
  • Disable Presentation Services if not required for business operations, or isolate it on a separate subnet with strict access controls.
  • Monitor SOAP traffic for abnormal patterns and configure alerts for suspicious activity.

Generated by OpenCVE AI on September 20, 2026 at 08:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege SOAP Exploit Allows Full Takeover of Oracle Business Intelligence Platform

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SOAP in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-94

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SOAP in Oracle Business Intelligence Enterprise Edition
Weaknesses CWE-94

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:37.789Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83295

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:23.185Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:42.307

Modified: 2026-09-17T14:17:40.130

Link: CVE-2026-83295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management