Junglewise Threat Intelligence

CVE-2026-83299: Oracle Business Intelligence Enterprise Edition remote code execution in Analytics Web General

CVE-2026-83299 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is an enterprise analytics and reporting platform used to create dashboards and reports from business data. An unauthenticated attacker can exploit a difficult-to-exploit vulnerability in the web interface to achieve complete compromise of the system, potentially exposing sensitive business intelligence data and disrupting analytics operations.

Technical details

This vulnerability in the Analytics Web General component of Oracle Business Intelligence Enterprise Edition allows an unauthenticated attacker with network access to compromise the affected system via HTTP. The vulnerability is difficult to exploit but can result in complete system takeover (remote code execution or equivalent), affecting confidentiality, integrity, and availability. The attack vector is network-based and requires no user interaction or authentication. Version 12.2.1.4.0 is known to be affected; patch status is not yet confirmed from the advisory references.

Affected products

  • Oracle Business Intelligence Enterprise Edition 12.2.1.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats