Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Compromise
Action: Immediate Patch
AI Analysis

Impact

The flaw is an insufficient privilege management issue (CWE-269) that allows a low‑privileged network user to abuse the BI server’s HTTP interface. Successful exploitation results in full takeover of the Oracle Business Intelligence Enterprise Edition, granting an attacker complete control over the platform and enabling loss of confidentiality, integrity, and availability of all BI data and services.

Affected Systems

Oracle Business Intelligence Enterprise Edition is affected in versions 8.2.0.0.0 and 26.01.0.0.0. Attackers can reach the vulnerable component via the standard HTTP interface exposed on the network.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 signals high severity, while the EPSS score of less than 1% indicates a low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over HTTP and does not require user interaction; only low privileges are necessary on the BI server to successfully compromise it.

Generated by OpenCVE AI on September 20, 2026 at 08:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied hotfix or upgrade to a patched version of Oracle Business Intelligence Enterprise Edition that addresses the privilege escalation flaw.
  • Restrict external HTTP access to the BI server by filtering inbound traffic with firewall rules or by placing the server behind a VPN, limiting exposure to trusted hosts only.
  • Enforce strict authentication and remove any default or overly permissive user accounts to enforce least privilege, ensuring that only authorized accounts can access sensitive BI functionality.

Generated by OpenCVE AI on September 20, 2026 at 08:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Enterprise BI Remote Compromise via Low‑Privilege HTTP Exploit

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploitation Compromise Oracle BI Enterprise Edition
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploitation Compromise Oracle BI Enterprise Edition
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Intelligence
CPEs cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*
Vendors & Products Oracle
Oracle business Intelligence
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:26.110Z

Reserved: 2026-08-31T15:40:57.353Z

Link: CVE-2026-83335

cve-icon Vulnrichment

Updated: 2026-09-17T12:59:33.404Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:46.770

Modified: 2026-09-17T14:17:41.997

Link: CVE-2026-83335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management