Junglewise Threat Intelligence

CVE-2026-83325: Oracle Business Intelligence Enterprise Edition privilege escalation in Platform Security

CVE-2026-83325 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is a data analytics and reporting platform used by enterprises to analyze business data. A privilege escalation vulnerability in the Platform Security component allows high-privileged attackers with network access to fully compromise the system, potentially gaining complete control over analytics data, dashboards, and the ability to manipulate or steal business intelligence information.

Technical details

The vulnerability is a privilege escalation flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition, reachable via HTTP from the network. It requires an attacker to already have high-level privileges on the system, though no user interaction is needed. Successful exploitation results in complete system compromise (confidentiality, integrity, and availability impacts). The vulnerability affects versions 8.2.0.0.0 and 26.01.0.0.0. Oracle has released security patches through their official advisories; customers should apply updates from Oracle's security bulletin immediately.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats