Junglewise Threat Intelligence

CVE-2026-83298: Oracle BI Publisher privilege escalation in BI Platform Security

CVE-2026-83298 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is an analytics and reporting tool used to create and distribute business intelligence reports. A high-privilege vulnerability allows an authenticated attacker with network access to completely compromise the system, potentially gaining full control over report generation, data access, and system operations.

Technical details

This is a privilege escalation vulnerability in the BI Platform Security component of Oracle BI Publisher. The vulnerability is easily exploitable and requires a high-privileged attacker with network access via HTTP; no additional user interaction is needed. Successful exploitation allows an attacker to achieve complete compromise of the BI Publisher system, impacting confidentiality, integrity, and availability. The affected version is 12.2.1.4.0. Oracle has released or plans to release patches as part of their security updates.

Affected products

  • Oracle BI Publisher 12.2.1.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats