Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation
Action: Patch Now
AI Analysis

Impact

A flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition allows a malicious actor who already possesses high‑privileged network credentials to gain full control of the affected BI instance. The vulnerability is triggered over ordinary HTTP traffic and, once exploited, it can compromise confidentiality, integrity, and availability of all business data housed in the instance. The weakness fits categories of bad authorization and privilege escalation, exposing the system to remote takeover when the conditions are met.

Affected Systems

Oracle Corporation’s Oracle Business Intelligence Enterprise Edition is affected in versions 8.2.0.0.0 and 26.01.0.0.0. The product is part of Oracle Analytics, and the vulnerability manifests through the HTTP interface of the BI platform.

Risk and Exploitability

The CVSS v3.1 base score of 7.2 indicates moderate to high severity. The EPSS score of less than 1% suggests the vulnerability has not yet been widely exploited, and it is not listed in the CISA KEV catalog. Because the flaw requires high‑privileged credentials and can be reached from the network, the potential impact is a full takeover of the BI instance if an attacker can inject malicious traffic over HTTP. The risk remains significant for any environment that exposes the BI platform to external access without prior high‑level authentication.

Generated by OpenCVE AI on September 20, 2026 at 08:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a non‑affected version as recommended by Oracle, which addresses the underlying improper privilege management flaw (CWE‑269).
  • Restrict external HTTP access to the BI instance using firewall rules or VPN and enforce network segmentation to reduce attack surface for privilege escalation.
  • Harden authentication and authorization controls by enforcing rigorous privilege checks, ensuring that high‑privileged credentials are properly validated and not granted excessive rights; monitor audit logs for suspicious high‑privilege activity.

Generated by OpenCVE AI on September 20, 2026 at 08:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via HTTP in Oracle Business Intelligence Enterprise Edition

Fri, 18 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Compromise via HTTP in Oracle BI Enterprise Edition
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Compromise via HTTP in Oracle BI Enterprise Edition
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:26.725Z

Reserved: 2026-08-31T15:40:57.353Z

Link: CVE-2026-83325

cve-icon Vulnrichment

Updated: 2026-09-17T12:59:47.647Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:45.660

Modified: 2026-09-17T14:17:41.537

Link: CVE-2026-83325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T01:45:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management