Sceawere
Vulnerability Detail
CVE-2026-71122UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OBIEE Platform Security Privilege Takeover
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Business Intelligence Enterprise Edition
- Attack Type
- Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.0",
"pubDate": "2026-08-18T21:18:12.947Z",
"pubdate": "2026-08-18T21:18:12.947Z",
"executiveSummary": "A difficult-to-exploit security vulnerability has been identified within the Platform Security component of Oracle Business Intelligence Enterprise Edition, impacting version 26.01.0.0.0. This vulnerability exposes the application to remote compromise via network access over HTTP. Successful exploitation requires an attacker to possess high privileges and overcome high attack complexity barriers, but can result in the complete takeover of the affected product.\nDue to a scope change characteristic, successful attacks against Oracle Business Intelligence Enterprise Edition may also significantly impact additional downstream or integrated products beyond the immediate boundary of the vulnerable component. The potential impact encompasses complete loss of confidentiality, integrity, and availability, yielding a CVSS 3.1 Base Score of 8.0.\nGiven the severity of a full system takeover, organizations running the affected version must treat this advisory with high urgency. Defensive postures should center on restricting high-privileged network access, enforcing stringent authentication controls, and applying vendor-supplied updates or patches as soon as they become available.",
"technicalDetails": "The vulnerability resides in the Platform Security component of Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0. The root cause stems from insecure handling of security contexts or privilege validation flaws within the platform security architecture, allowing a high-privileged actor to execute unauthorized administrative actions.\nExploitation of this vulnerability requires network access via the HTTP protocol. The attacker must already possess high privileges within the application environment, meaning unauthorized anonymous or low-privileged users cannot directly trigger the flaw. Furthermore, the attack complexity is rated as high, indicating that specific, difficult-to-reproduce preconditions or race conditions must be met by the adversary to successfully weaponize the flaw.\nThe step-by-step attack flow begins with the high-privileged adversary establishing network connectivity to the Oracle Business Intelligence Enterprise Edition HTTP interface. By crafting a specialized sequence of requests targeting the vulnerable Platform Security component, the attacker bypasses intended architectural constraints despite their existing privileges. Because of the scope change (S:C) vector, the crafted payload or execution flow compromises security boundaries that extend beyond the primary application instance, potentially affecting interconnected systems or shared security domains.\nUpon successful exploitation, the adversary achieves total control over the Oracle Business Intelligence Enterprise Edition environment, leading to a complete takeover. This grants the attacker unauthorized read, write, and execute capabilities over sensitive data repositories, system configurations, and underlying application processes, resulting in severe degradation or total compromise of confidentiality, integrity, and availability across the affected ecosystem."
}