Improper input validation in Oracle Business Intelligence Enterprise Edition - CVE-2026-27727

 

Improper input validation in Oracle Business Intelligence Enterprise Edition - CVE-2026-27727

Published: April 22, 2026


Vulnerability identifier: #VU126752
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27727
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Platform Security (Mchange Commons Java) component in Oracle Business Intelligence Enterprise Edition. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Affected software

Oracle Business Intelligence Enterprise Edition
MongoDB Enterprise Advanced with IBM
webMethods BPM
Crucible Server
Crucible Data Center
Bamboo Data Center
IBM Qradar SIEM
openSUSE Leap
openEuler
mchange-commons-help
mchange-commons
mchange-commons-javadoc
c3p0
c3p0-javadoc
release-notes-susemanager-proxy
release-notes-susemanager
Red Hat Camel for Spring Boot

How to mitigate CVE-2026-27727

Install updates from vendor's website.

Crucible Server - update to 4.9.9
Crucible Data Center - update to 4.9.9
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
MongoDB Enterprise Advanced with IBM - update to 8.0.22
Bamboo Data Center - addressed in versions 9.6.26, 10.2.19, 12.1.7
webMethods BPM - update to 11.1 Fix 6
mchange-commons-help - update to 0.2.11-12
mchange-commons - update to 0.2.11-12
mchange-commons-javadoc - update to 0.2.20-150400.3.3.1
mchange-commons - update to 0.2.20-150400.3.3.1
c3p0 - update to 0.9.5.5-150400.3.5.1
c3p0-javadoc - update to 0.9.5.5-150400.3.5.1
release-notes-susemanager-proxy - update to 4.3.17-150400.3.107.1
release-notes-susemanager - update to 4.3.17-150400.3.151.1
Red Hat Camel for Spring Boot - update to 4.14.4

External References

Related Security Bulletins