Sceawere

Vulnerability Detail

CVE-2026-71094UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OBEE Presentation Services Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Business Intelligence Enterprise Edition
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-08-18T21:18:09.563Z",
  "pubdate": "2026-08-18T21:18:09.563Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Presentation Services component of Oracle Business Intelligence Enterprise Edition, specifically affecting version 12.2.1.4.0. This security flaw enables a low-privileged attacker who has obtained local logon access to the underlying infrastructure hosting the application to compromise the entire Oracle Business Intelligence Enterprise Edition environment. Successful exploitation of this vulnerability results in a complete system takeover, impacting confidentiality, integrity, and availability with a maximum CVSS 3.1 Base Score of 7.3. The attack vector is localized, requiring the attacker to have low privileges and local access to the target infrastructure. Furthermore, successful execution mandates human interaction from a victim other than the attacker, denoting a requirement for social engineering or user-assisted exploitation chains to achieve the desired malicious objective. Given the severity of the potential impact, organizations utilizing the affected version face significant operational and security risks if unauthorized local actors successfully execute the attack.",
  "technicalDetails": "The vulnerability resides in the Presentation Services component of Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0. The attack vector is classified as local (AV:L), meaning the adversary must already possess physical or remote interactive logon capabilities to the operating system infrastructure where the affected software executes. The attack complexity is low (AC:L), indicating that once the prerequisite access and conditions are met, the exploitation steps do not require sophisticated cryptographic breaking or complex race conditions. The privilege requirement is low (PR:L), signifying that the attacker does not need administrative or root access to initiate the exploit chain; standard user credentials on the host OS are sufficient. However, the metric dictates a requirement for user interaction (UI:R), meaning that a secondary user must perform an action—such as interacting with a crafted interface, opening a file, or processing a session—to facilitate the exploit execution flow. The scope is unmodified (S:U), as the compromise remains contained within the security authority boundaries of the targeted Oracle Business Intelligence Enterprise Edition instance, yet it still yields high impacts across all three CIA triads (C:H/I:H/A:H). The step-by-step attack flow involves the low-privileged attacker establishing a local session on the host infrastructure, leveraging local execution vectors or accessible file systems associated with Presentation Services, and engineering a scenario where required human interaction is elicited from a secondary user or administrator. By combining the low-privileged local access with the necessary user interaction, the attacker is able to manipulate application logic or runtime execution parameters within the vulnerable Presentation Services component. This manipulation leads directly to unauthorized privilege escalation or command execution within the context of the application service account, ultimately culminating in the full takeover of the Oracle Business Intelligence Enterprise Edition deployment and granting the adversary complete control over enterprise intelligence data and underlying application functions."
}
CVE-2026-71094: OBEE Presentation Services Privilege Escalation Vulnerability (HIGH Severity, CVSS: 7.3) - Sceawere