Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation and System Takeover
Action: Immediate Patch
AI Analysis

Impact

The Platform Security component of Oracle Business Intelligence Enterprise Edition contains a flaw that lets a low‑privileged user who is logged into the underlying infrastructure gain control of the BI platform. An attacker can obtain full takeover, exposing, altering or deleting confidential data and disrupting service availability. The weakness is represented by CWE-269 and carries a CVSS 3.1 base score of 7.5, indicating severe confidentiality, integrity and availability impacts.

Affected Systems

Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0 deployed on the organization’s infrastructure is vulnerable. The flaw is not limited to the BI platform; the scope change means that other applications running on the same host could also be compromised once the BI platform is taken over.

Risk and Exploitability

The CVSS vector AV:L/AC:H/PR:L/UI:R/S:C indicates that exploitation requires local access, high attack complexity, low attacker privileges, and user interaction from a third party, making automated attacks difficult. The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been observed. However, when successfully exploited the attacker can achieve complete system takeover, posing a severe risk for environments that run the affected version of Oracle BI.

Generated by OpenCVE AI on September 20, 2026 at 07:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch for Oracle Business Intelligence Enterprise Edition 26.01.0.0.0 that addresses the Platform Security vulnerability.
  • Restrict local access by implementing strict least‑privilege controls, ensuring that only authorized personnel can log into the infrastructure hosting the BI platform.
  • Continuously monitor system activity for signs of privilege escalation or unauthorized changes, and employ file‑integrity monitoring and privileged‑access audit logs to detect potential compromise.

Generated by OpenCVE AI on September 20, 2026 at 07:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Takeover in Oracle Business Intelligence Enterprise Edition

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Takeover in Oracle Business Intelligence Enterprise Edition 26.01.0.0.0
Weaknesses CWE-284

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Takeover in Oracle Business Intelligence Enterprise Edition 26.01.0.0.0
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:13.983Z

Reserved: 2026-08-31T15:40:57.353Z

Link: CVE-2026-83323

cve-icon Vulnrichment

Updated: 2026-09-17T12:50:16.651Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:45.433

Modified: 2026-09-17T14:17:41.423

Link: CVE-2026-83323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T01:45:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management