Junglewise Threat Intelligence

CVE-2026-83317: Oracle Business Intelligence Enterprise Edition privilege escalation in Installation

CVE-2026-83317 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is an analytics platform used by enterprises to process and visualize business data. A vulnerability in the installation component allows a low-privileged user with local system access to escalate privileges and take over the entire application, compromising confidentiality, integrity, and availability of analytics data and reports.

Technical details

This is a local privilege escalation vulnerability in the installation component of Oracle Business Intelligence Enterprise Edition. The vulnerability requires the attacker to have low-privilege logon access to the infrastructure where the application executes. With network access not required and minimal security controls bypassed (low complexity), a local attacker can achieve complete compromise of the application, including unauthorized access to data, modification of reports and configurations, and denial of service. The affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Patches or mitigations should be obtained from Oracle.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats