Junglewise Threat Intelligence

CVE-2026-83323: Oracle Business Intelligence Enterprise Edition privilege escalation

CVE-2026-83323 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is an analytics and reporting platform used by enterprises to analyze and visualize business data. This vulnerability allows a low-privileged user with local access to the server to gain full control of the application through social engineering (requiring another user's interaction). A successful attack could lead to complete compromise of the analytics system, affecting data confidentiality, integrity, and availability across the entire platform.

Technical details

This is a privilege escalation vulnerability in Oracle Business Intelligence Enterprise Edition (version 26.01.0.0.0) affecting the Platform Security component. The vulnerability requires local access to the infrastructure where the application runs, along with low-privilege credentials and user interaction from another person. The attack vector is local with high exploitation complexity, indicating that specific conditions or user actions are needed to exploit it successfully. A successful exploit results in complete takeover of the application with scope change, meaning the compromise can significantly impact other products in the same environment. Patch availability and specific technical remediation details were not accessible in the advisory materials.

Affected products

  • Oracle Business Intelligence Enterprise Edition 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats