Sceawere

Vulnerability Detail

CVE-2026-71122UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OBIEE Platform Security Privilege Takeover

Vulnerability Metadata

Severity
High
Score / CVSS
8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Business Intelligence Enterprise Edition
Attack Type
Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition.
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.0",
  "pubDate": "2026-08-18T21:18:12.947Z",
  "pubdate": "2026-08-18T21:18:12.947Z",
  "executiveSummary": "A difficult-to-exploit security vulnerability has been identified within the Platform Security component of Oracle Business Intelligence Enterprise Edition, impacting version 26.01.0.0.0. This vulnerability exposes the application to remote compromise via network access over HTTP. Successful exploitation requires an attacker to possess high privileges and overcome high attack complexity barriers, but can result in the complete takeover of the affected product.\nDue to a scope change characteristic, successful attacks against Oracle Business Intelligence Enterprise Edition may also significantly impact additional downstream or integrated products beyond the immediate boundary of the vulnerable component. The potential impact encompasses complete loss of confidentiality, integrity, and availability, yielding a CVSS 3.1 Base Score of 8.0.\nGiven the severity of a full system takeover, organizations running the affected version must treat this advisory with high urgency. Defensive postures should center on restricting high-privileged network access, enforcing stringent authentication controls, and applying vendor-supplied updates or patches as soon as they become available.",
  "technicalDetails": "The vulnerability resides in the Platform Security component of Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0. The root cause stems from insecure handling of security contexts or privilege validation flaws within the platform security architecture, allowing a high-privileged actor to execute unauthorized administrative actions.\nExploitation of this vulnerability requires network access via the HTTP protocol. The attacker must already possess high privileges within the application environment, meaning unauthorized anonymous or low-privileged users cannot directly trigger the flaw. Furthermore, the attack complexity is rated as high, indicating that specific, difficult-to-reproduce preconditions or race conditions must be met by the adversary to successfully weaponize the flaw.\nThe step-by-step attack flow begins with the high-privileged adversary establishing network connectivity to the Oracle Business Intelligence Enterprise Edition HTTP interface. By crafting a specialized sequence of requests targeting the vulnerable Platform Security component, the attacker bypasses intended architectural constraints despite their existing privileges. Because of the scope change (S:C) vector, the crafted payload or execution flow compromises security boundaries that extend beyond the primary application instance, potentially affecting interconnected systems or shared security domains.\nUpon successful exploitation, the adversary achieves total control over the Oracle Business Intelligence Enterprise Edition environment, leading to a complete takeover. This grants the attacker unauthorized read, write, and execute capabilities over sensitive data repositories, system configurations, and underlying application processes, resulting in severe degradation or total compromise of confidentiality, integrity, and availability across the affected ecosystem."
}
CVE-2026-71122: OBIEE Platform Security Privilege Takeover (HIGH Severity, CVSS: 8.0) - Sceawere