Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L).
Published: 2026-09-15
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote unauthorized data modification and partial denial of service
Action: Patch immediately
AI Analysis

Impact

Oracle Business Intelligence Enterprise Edition contains a flaw in its Analytics Web General component that fails to enforce proper authentication checks. The weakness is identified as CWE‑284 (Improper Authentication). This flaw allows an unauthenticated attacker who can reach the system over HTTP to create, delete, or modify critical data and to induce a partial denial of service. The vulnerability also permits unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data.

Affected Systems

Oracle Corporation’s Oracle Business Intelligence Enterprise Edition is affected. The vulnerable versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.

Risk and Exploitability

The CVSS 3.1 base score of 8.9 indicates high severity with confidentiality, integrity, and availability impacts. The EPSS score of less than 1 % indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can reach the affected servers over HTTP (network access) and, without authentication, achieve unauthorized data manipulation or a partial denial‑of-service, potentially exposing all data the application can access.

Generated by OpenCVE AI on September 20, 2026 at 08:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s latest security patch or upgrade to a version that is not affected.
  • Restrict direct HTTP access to the BI servers by placing them behind a firewall or a VPN.
  • Enable detailed logging and monitor for signs of unauthorized data modifications or partial denial‑of‑service activity.

Generated by OpenCVE AI on September 20, 2026 at 08:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification in Oracle Business Intelligence Enterprise Edition

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Allows Data Modification and Partial Denial of Service in Oracle BI Enterprise Edition
Weaknesses CWE-285

Wed, 16 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Allows Data Modification and Partial Denial of Service in Oracle BI Enterprise Edition
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 8.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:49.344Z

Reserved: 2026-08-31T15:40:57.352Z

Link: CVE-2026-83304

cve-icon Vulnrichment

Updated: 2026-09-18T18:16:11.868Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:43.307

Modified: 2026-09-18T19:16:54.050

Link: CVE-2026-83304

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T01:45:16Z

Weaknesses