CVE-2026-71107: High severity Oracle Oracle Business Intelligence Enterprise Edition vulnerability
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Affected supported versions are 8.2.0.0.0 and 26.01.0.0.0 of Oracle Business Intelligence Enterprise Edition in the Analytics Server component.
Does exploitation require authentication or user interaction?
No. An unauthenticated attacker can exploit the issue over HTTP with network access, and no user interaction is required.
What is the potential impact of successful exploitation?
Successful exploitation can give an attacker unauthorized access to critical data or complete access to all data accessible through Oracle Business Intelligence Enterprise Edition.