Junglewise Threat Intelligence

CVE-2026-83071: Oracle Business Intelligence Enterprise Edition privilege escalation in Machine Learning

CVE-2026-83071 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is an analytics platform used for business reporting and data analysis. A privilege escalation vulnerability in its Machine Learning component allows a low-privileged local user with system access to fully compromise the system and gain complete control over analytics data and operations.

Technical details

This is a privilege escalation vulnerability in the Machine Learning component of Oracle Business Intelligence Enterprise Edition. It requires local access to the infrastructure where the product executes and valid logon credentials (low privilege level), with no user interaction needed. A successful exploit allows an authenticated local attacker to achieve full system compromise, including complete confidentiality, integrity, and availability impact. The vulnerability affects versions 8.2.0.0.0 and 26.01.0.0.0. Patch availability status is not confirmed in the available advisory details.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats