Sceawere
Vulnerability Detail
CVE-2026-71098UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OBEE Platform Security Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Business Intelligence Enterprise Edition
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.0",
"pubDate": "2026-08-18T21:18:10.030Z",
"pubdate": "2026-08-18T21:18:10.030Z",
"executiveSummary": "An elevation of privilege vulnerability exists within the Platform Security component of Oracle Business Intelligence Enterprise Edition (version 26.01.0.0.0). This vulnerability presents significant risk to confidentiality, integrity, and availability, yielding a CVSS 3.1 base score of 7.0 with the vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.\nSuccessful exploitation of this flaw allows a low-privileged attacker who has obtained local logon access to the underlying infrastructure hosting the application to achieve a complete system takeover of Oracle Business Intelligence Enterprise Edition. The vulnerability is characterized as difficult to exploit, requiring specific high-complexity conditions met by the attacker in the local environment.\nThe implications of a successful attack include total compromise of sensitive business intelligence data, unauthorized modification or deletion of system resources, and denial of service across the affected Oracle Business Intelligence Enterprise Edition deployment. Mitigation requires adherence to vendor-supplied updates and rigorous hardening of the host infrastructure execution environment.",
"technicalDetails": "The vulnerability resides within the Platform Security component of Oracle Business Intelligence Enterprise Edition, specifically affecting version 26.01.0.0.0. The root cause stems from insecure handling of security contexts, permissions, or resource access controls within the underlying execution infrastructure.\nExploitation of this vulnerability requires local access to the infrastructure where Oracle Business Intelligence Enterprise Edition executes. An attacker must possess low privileges on the host operating system and successfully establish a local logon session. The attack vector is classified as Local (AV:L), meaning network-based exploitation is not feasible without prior access to the host.\nThe attack complexity is rated as High (AC:H), indicating that successful exploitation demands precise pre-conditions, race conditions, or specific configuration states within the execution environment. Furthermore, user interaction is not required (UI:N), allowing the attacker to execute the attack chain independently once local access and conditions are established.\nThe attack flow proceeds as follows: First, the low-privileged attacker authenticates locally to the target infrastructure hosting the Oracle Business Intelligence Enterprise Edition instance. Second, leveraging local visibility or interaction with the Platform Security component, the attacker exploits logic flaws or permission mismanagement within the execution environment. Third, due to insufficient isolation or improper authorization checks, the attacker escalates privileges from a low-privileged context to administrative or system-level control over the Oracle Business Intelligence Enterprise Edition service.\nUpon successful exploitation, the post-exploitation impact results in a total takeover of the Oracle Business Intelligence Enterprise Edition application. This grants the adversary full read, write, and execute capabilities over sensitive analytical data, configuration files, and core application binaries, severely compromising the CIA triad (Confidentiality, Integrity, and Availability)."
}