Junglewise Threat Intelligence

CVE-2026-83288: Oracle Business Intelligence Enterprise Edition privilege escalation in BI Search

CVE-2026-83288 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a data analytics platform used by organizations to create reports and dashboards from business data. A vulnerability in the BI Search component allows a low-privileged user with local access to the system to gain complete control of the Analytics application, potentially compromising sensitive business intelligence data and reports.

Technical details

The vulnerability exists in the BI Search component of Oracle Business Intelligence Enterprise Edition and is exploitable by a low-privileged attacker with logon access to the infrastructure. The vulnerability allows privilege escalation to take over the entire Oracle Business Intelligence Enterprise Edition system. No authentication to the application itself is required—only local infrastructure access—and exploitation is straightforward (CVSS Access Complexity: Low). Successful exploitation results in complete compromise of confidentiality, integrity, and availability of the Analytics system.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed: Oracle published advisory

References

Related threats