Junglewise Threat Intelligence

CVE-2026-83273: Oracle Business Intelligence Enterprise Edition privilege escalation in Platform Security

CVE-2026-83273 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a data analytics platform used by organizations to analyze business data and create reports. A high-privileged attacker with network access can exploit a vulnerability in the Platform Security component to completely compromise the system, potentially gaining unauthorized access to sensitive analytics data and affecting business reporting operations.

Technical details

The vulnerability exists in the Platform Security component of Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0. It is easily exploitable and requires a high-privileged attacker with network access via HTTP. The attack vector is network-based with no user interaction required. Successful exploitation allows an attacker to achieve complete compromise of the system, affecting confidentiality, integrity, and availability of the platform. A patch is expected from Oracle's security update cycle.

Affected products

  • Oracle Business Intelligence Enterprise Edition 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats