
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71122 is a security vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of the Oracle Analytics product family. It affects version 26.01.0.0.0 and was disclosed on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU) for August 2026. The vulnerability carries a CVSS v3.1 base score of 8.0 (High), reflecting its potential for complete product takeover with scope change to additional products (Oracle Advisory, NVD).
The vulnerability resides in the Platform Security component of Oracle Business Intelligence Enterprise Edition and is exploitable over HTTP by a high-privileged attacker. The attack complexity is rated High, meaning exploitation requires specific conditions or configurations to be met beyond the attacker's control. The vulnerability results in a scope change, meaning a successful exploit can affect resources beyond the vulnerable component itself — potentially impacting other Oracle Analytics products. No CWE classification has been formally assigned by NVD at this time, and no public technical write-ups or proof-of-concept code have been identified (Oracle Advisory, NVD).
Successful exploitation of CVE-2026-71122 can result in complete takeover of the affected Oracle Business Intelligence Enterprise Edition instance, with high impacts to confidentiality, integrity, and availability. Due to the scope change characteristic of this vulnerability, attacks may significantly impact additional connected Oracle Analytics products beyond the directly targeted system. This could expose sensitive business intelligence data, allow unauthorized modification of reports and configurations, and disrupt availability of analytics services (Oracle Advisory).
There is no public proof-of-concept exploit code known at this time, and no evidence of active in-the-wild exploitation has been reported. The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges and involves high attack complexity, which limits the pool of potential attackers (Oracle Advisory).
Oracle has released a patch for CVE-2026-71122 as part of the August 2026 Critical Security Patch Update (CSPU). Organizations running Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0 should apply the patch immediately. As a temporary workaround prior to patching, Oracle recommends implementing network access controls to restrict HTTP access to the OBIEE instance to only authorized, high-privileged personnel, and limiting administrative account access to the minimum necessary users. Oracle strongly cautions that workarounds do not address the underlying vulnerability and patching remains the only long-term solution (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."