Junglewise Threat Intelligence

CVE-2026-83297: Oracle BI Publisher privilege escalation via LDAP

CVE-2026-83297 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is an analytics and reporting component used within Oracle Analytics to create and manage business reports. A vulnerability in its security platform allows a low-privileged network attacker to escalate privileges and gain unauthorized access to, modify, or delete sensitive business data. This could compromise confidentiality and integrity of critical analytics and reports accessible through the platform.

Technical details

This is a privilege escalation vulnerability in Oracle BI Publisher's BI Platform Security component, exploitable via LDAP (Lightweight Directory Access Protocol). The flaw requires network access and a low-privileged account to trigger, but no user interaction. Successful exploitation allows an authenticated attacker to read, modify, or delete critical data across the BI Publisher instance. The vulnerability affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. A patch or mitigation is expected from Oracle, though specific remediation details are not yet available in accessible advisories.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats