Junglewise Threat Intelligence

CVE-2026-83286: Oracle Business Intelligence Enterprise Edition authentication bypass

CVE-2026-83286 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a reporting and analytics platform used by enterprises to analyze business data and make decisions. A vulnerability in the platform's security component allows an unauthenticated attacker to gain complete control over the system through the network, potentially exposing or altering sensitive business intelligence data and reports. This could result in data theft, manipulation of analytics, or service disruption.

Technical details

This is an authentication bypass or unauthorized access vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition, exploitable remotely over HTTP without requiring user credentials. The vulnerability is difficult to exploit but allows an unauthenticated network attacker to achieve complete system compromise with high impact on confidentiality, integrity, and availability. Affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Oracle has released a security patch as part of their September 2026 critical patch update. No active exploitation in the wild has been reported at time of publication.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed: Vulnerability disclosed in Oracle's Critical Patch Update

References

Related threats