Junglewise Threat Intelligence

CVE-2026-83290: Oracle Business Intelligence Enterprise Edition privilege escalation in Platform Security

CVE-2026-83290 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is an analytics and reporting platform used to process and visualize business data. A privilege escalation vulnerability in its Platform Security component allows a low-privileged user with local system access to take complete control of the application, potentially exposing sensitive analytics data, modifying reports, or disrupting business intelligence operations.

Technical details

This is a privilege escalation vulnerability affecting Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0 and 26.01.0.0.0. The vulnerability exists in the Platform Security component and can be exploited by a low-privileged attacker with logon access to the host infrastructure. The attack vector is local (requires direct or system-level access to the machine running the application), requires low privilege credentials and no user interaction. Successful exploitation allows an attacker to achieve complete compromise of the application, including confidentiality, integrity, and availability impacts. Patches are assumed to be available through Oracle's standard security update channels, though specific remediation details are not provided in the advisory summary.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats