Junglewise Threat Intelligence

CVE-2026-83282: Oracle Business Intelligence Enterprise Edition privilege escalation in Platform Security

CVE-2026-83282 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a widely-deployed analytics platform used by enterprises to create reports and dashboards. A critical vulnerability in its Platform Security component allows an attacker with low-level network access to completely compromise the system and potentially attack other connected applications. A successful exploit could lead to unauthorized access to sensitive business data, system takeover, and operational disruption.

Technical details

The vulnerability is an easily exploitable flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0. It allows an attacker with low privileges and network access via HTTP to escalate privileges and gain full control of the system. The vulnerability has cross-system impact (scope change), meaning successful exploitation could be used as a stepping stone to compromise other products on the network. Patches are expected as part of Oracle's security update cycle, though immediate patching or mitigation of version 12.2.1.4.0 is strongly recommended.

Affected products

  • Oracle Business Intelligence Enterprise Edition 12.2.1.4.0

Timeline

  • 2026-09-15: disclosed
  • other: Oracle security advisory published; exploit status unknown at time of advisory

References

Related threats