CVE-2026-71122
Oracle Business Intelligence Enterprise Edition (OBIEE) vulnerability analysis and mitigation

Overview

CVE-2026-71122 is a security vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of the Oracle Analytics product family. It affects version 26.01.0.0.0 and was disclosed on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU) for August 2026. The vulnerability carries a CVSS v3.1 base score of 8.0 (High), reflecting its potential for complete product takeover with scope change to additional products (Oracle Advisory, NVD).

Technical details

The vulnerability resides in the Platform Security component of Oracle Business Intelligence Enterprise Edition and is exploitable over HTTP by a high-privileged attacker. The attack complexity is rated High, meaning exploitation requires specific conditions or configurations to be met beyond the attacker's control. The vulnerability results in a scope change, meaning a successful exploit can affect resources beyond the vulnerable component itself — potentially impacting other Oracle Analytics products. No CWE classification has been formally assigned by NVD at this time, and no public technical write-ups or proof-of-concept code have been identified (Oracle Advisory, NVD).

Impact

Successful exploitation of CVE-2026-71122 can result in complete takeover of the affected Oracle Business Intelligence Enterprise Edition instance, with high impacts to confidentiality, integrity, and availability. Due to the scope change characteristic of this vulnerability, attacks may significantly impact additional connected Oracle Analytics products beyond the directly targeted system. This could expose sensitive business intelligence data, allow unauthorized modification of reports and configurations, and disrupt availability of analytics services (Oracle Advisory).

Exploitability

There is no public proof-of-concept exploit code known at this time, and no evidence of active in-the-wild exploitation has been reported. The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges and involves high attack complexity, which limits the pool of potential attackers (Oracle Advisory).

Mitigation and workarounds

Oracle has released a patch for CVE-2026-71122 as part of the August 2026 Critical Security Patch Update (CSPU). Organizations running Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0 should apply the patch immediately. As a temporary workaround prior to patching, Oracle recommends implementing network access controls to restrict HTTP access to the OBIEE instance to only authorized, high-privileged personnel, and limiting administrative account access to the minimum necessary users. Oracle strongly cautions that workarounds do not address the underlying vulnerability and patching remains the only long-term solution (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Business Intelligence Enterprise Edition (OBIEE) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71122HIGH8
  • Oracle Business Intelligence Enterprise Edition (OBIEE) logoOracle Business Intelligence Enterprise Edition (OBIEE)
  • cpe:2.3:a:oracle:business_intelligence
NoNoAug 18, 2026
CVE-2026-71097HIGH7.8
  • Oracle Business Intelligence Enterprise Edition (OBIEE) logoOracle Business Intelligence Enterprise Edition (OBIEE)
  • cpe:2.3:a:oracle:business_intelligence
NoNoAug 18, 2026
CVE-2026-71107HIGH7.5
  • Oracle Business Intelligence Enterprise Edition (OBIEE) logoOracle Business Intelligence Enterprise Edition (OBIEE)
  • cpe:2.3:a:oracle:business_intelligence
NoNoAug 18, 2026
CVE-2026-71099HIGH7.2
  • Oracle Business Intelligence Enterprise Edition (OBIEE) logoOracle Business Intelligence Enterprise Edition (OBIEE)
  • cpe:2.3:a:oracle:business_intelligence
NoNoAug 18, 2026
CVE-2026-71098HIGH7
  • Oracle Business Intelligence Enterprise Edition (OBIEE) logoOracle Business Intelligence Enterprise Edition (OBIEE)
  • cpe:2.3:a:oracle:business_intelligence
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management