Junglewise Threat Intelligence

CVE-2026-83292: Oracle Business Intelligence Enterprise Edition auth bypass in Platform Security

CVE-2026-83292 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a data analytics platform used by enterprises to analyze and visualize business data. This vulnerability allows a low-privileged user with network access to the platform to gain complete control over the system, potentially exposing or manipulating sensitive business intelligence and analysis data.

Technical details

This is an authentication or authorization bypass vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition. The vulnerability requires network access via HTTP and a low-privileged account (PR:L), but has a high attack complexity (AC:H), suggesting specific conditions or exploitation techniques are needed. Successful exploitation results in complete compromise of the system with high impact to confidentiality, integrity, and availability. Affected versions are 8.2.0.0.0 and 26.01.0.0.0. Patch availability has not been confirmed from the available advisory text.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats