Junglewise Threat Intelligence

CVE-2026-83321: Oracle Business Intelligence Enterprise Edition privilege escalation in Analytics Actions

CVE-2026-83321 · Severity: high · CVSS 8.5 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a data analytics platform used to analyze and visualize business data. A vulnerability in its Analytics Actions component allows a low-privileged attacker with network access to gain unauthorized access to sensitive data and modify critical information without proper authorization. This could expose confidential business intelligence data across connected systems.

Technical details

This is a privilege escalation vulnerability in the Analytics Actions component of Oracle Business Intelligence Enterprise Edition. The vulnerability is easily exploitable by a low-privileged, authenticated attacker via HTTP without user interaction required. An attacker can achieve unauthorized read access to critical data and unauthorized update/insert/delete access to some accessible data. The scope is marked as changed, indicating the impact extends beyond the vulnerable component to other Oracle Analytics products. Versions 8.2.0.0.0 and 26.01.0.0.0 are affected; patches are expected from Oracle's security advisory.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats