Junglewise Threat Intelligence

CVE-2026-83316: Oracle Business Intelligence Enterprise Edition privilege escalation in Platform Security

CVE-2026-83316 · Severity: high · CVSS 7 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a business analytics platform used to process and visualize corporate data. A vulnerability in its Platform Security component allows a low-privileged user with local system access to gain full administrative control of the system, potentially exposing or manipulating sensitive business intelligence data.

Technical details

A privilege escalation vulnerability exists in the Platform Security component of Oracle Business Intelligence Enterprise Edition version 26.01.0.0.0. The vulnerability requires local system access and valid user credentials but does not require user interaction, allowing an authenticated local attacker to escalate privileges and achieve complete system compromise. The vulnerability is classified as difficult to exploit due to the prerequisites and complexity of the attack path. Successful exploitation results in full compromise of the Oracle Business Intelligence Enterprise Edition system, including read/write access to all data and the ability to disable audit logging or disrupt service availability.

Affected products

  • Oracle Business Intelligence Enterprise Edition 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats