Junglewise Threat Intelligence

CVE-2026-83296: Oracle Business Intelligence Enterprise Edition privilege escalation in BI Search

CVE-2026-83296 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition (BIEE) is an analytics platform used to create dashboards and reports from business data. This vulnerability allows a low-privileged attacker to gain complete control over the entire BIEE system through a flaw in the BI Search component, potentially exposing sensitive business analytics data and disrupting analytics operations.

Technical details

This is a difficult-to-exploit privilege escalation vulnerability in the BI Search component of Oracle Business Intelligence Enterprise Edition, reachable via HTTP from the network. The vulnerability requires a low-privilege authenticated attacker and specific exploitation conditions (indicated by high AC), but successful exploitation results in complete compromise of the BIEE system including confidentiality, integrity, and availability impacts. Affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Patch availability and specific technical remediation steps are not documented in the available advisory text.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats