Junglewise Threat Intelligence

CVE-2026-83283: Oracle Business Intelligence Enterprise Edition unauthenticated remote code execution

CVE-2026-83283 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is an analytics platform used by enterprises to analyze and visualize business data. A critical flaw allows unauthenticated attackers to remotely take over the system via HTTP, potentially compromising all stored analytics data, dashboards, and customer insights. An attacker exploiting this vulnerability could gain complete control of the platform without requiring any credentials.

Technical details

This is an unauthenticated remote code execution vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0. The vulnerability is easily exploitable via the network and HTTP protocol without authentication or user interaction required. An attacker with network access can achieve complete compromise of the system, affecting confidentiality, integrity, and availability. The CVSS 3.1 score of 9.8 reflects the critical severity. Patch availability should be confirmed via Oracle's official security advisories.

Affected products

  • Oracle Business Intelligence Enterprise Edition 12.2.1.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats