Junglewise Threat Intelligence

CVE-2026-83289: Oracle Business Intelligence Enterprise Edition privilege escalation in Analytics Web

CVE-2026-83289 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a data analytics and reporting platform used by enterprises to analyze business data. A network-accessible vulnerability in its SOAP interface allows low-privileged users to gain complete control over the analytics system, potentially exposing sensitive business data and disrupting reporting operations critical to decision-making.

Technical details

A difficult-to-exploit privilege escalation vulnerability exists in the Analytics Web General component of Oracle Business Intelligence Enterprise Edition, exploitable via SOAP protocol. The vulnerability requires network access and a valid low-privileged account but no user interaction. Successful exploitation allows an attacker to achieve complete system takeover with full confidentiality, integrity, and availability impacts. Affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0; patch availability and details have not yet been disclosed.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats