Junglewise Threat Intelligence

CVE-2026-83322: Oracle Business Intelligence Enterprise Edition privilege escalation in Platform Security

CVE-2026-83322 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a data analytics and reporting platform used by enterprises to analyze business data. A high-privilege attacker with network access can exploit a vulnerability in the Platform Security component to take over the entire system, gaining full control over analytics data, dashboards, and reports. This affects versions 8.2.0.0.0 and 26.01.0.0.0 and can result in complete compromise of confidentiality, integrity, and availability of the analytics platform.

Technical details

This vulnerability in Oracle Business Intelligence Enterprise Edition's Platform Security component allows a high-privileged attacker with network access via HTTP to achieve complete system compromise. The attack is easily exploitable and does not require user interaction or special conditions. An attacker with high privileges can leverage the vulnerability to take over the entire Oracle Business Intelligence Enterprise Edition installation, potentially gaining control over authentication, data access, and system operations. Network-based exploitation is possible via HTTP protocol. Patches are expected from Oracle following the published advisory.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats