Junglewise Threat Intelligence

CVE-2026-83294: Oracle Business Intelligence Enterprise Edition privilege escalation in Platform Security

CVE-2026-83294 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is an analytics platform used by enterprises to process and analyze business data. A local privilege escalation vulnerability in the Platform Security component allows an attacker with infrastructure access to compromise the system through social engineering, potentially gaining full control over the analytics platform and the sensitive business data it contains.

Technical details

This is a local privilege escalation vulnerability in the Oracle Business Intelligence Enterprise Edition Platform Security component, affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability requires the attacker to have logon access to the infrastructure where the product executes and requires user interaction (social engineering or tricking another user), but no prior authentication to the application itself. Successful exploitation allows an unauthenticated attacker to achieve complete compromise (confidentiality, integrity, and availability) of the Business Intelligence Enterprise Edition system. No patch availability information is currently disclosed in the advisory.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats