CVE-2026-71122: High severity Oracle Oracle Business Intelligence Enterprise Edition vulnerability
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is realistically able to exploit this issue?
Exploitation requires a high-privileged attacker with network access to the affected Oracle Business Intelligence Enterprise Edition instance over HTTP. No user interaction is required, but the attack complexity is rated high.
Which version is identified as affected?
The affected supported version is Oracle Business Intelligence Enterprise Edition 26.01.0.0.0.
What is the potential impact of successful exploitation?
A successful attack can result in takeover of Oracle Business Intelligence Enterprise Edition, with high confidentiality, integrity, and availability impact. The scope change indicates that attacks may also significantly affect additional products.