Junglewise Threat Intelligence

CVE-2026-83293: Oracle Business Intelligence Enterprise Edition privilege escalation in FNDN

CVE-2026-83293 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a data analytics and reporting tool used across enterprises. A local privilege escalation vulnerability allows a low-privileged user with system access to gain complete control of the application, potentially exposing sensitive business intelligence data and analytics infrastructure.

Technical details

A local privilege escalation vulnerability exists in the FNDN component of Oracle Business Intelligence Enterprise Edition 12.2.1.4.0. The vulnerability is easily exploitable and requires only local logon access with low privileges and no user interaction. An attacker can achieve complete compromise of the application including confidentiality, integrity, and availability impacts. No patch availability information is currently available from the provided advisory.

Affected products

  • Oracle Business Intelligence Enterprise Edition 12.2.1.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats