Junglewise Threat Intelligence

CVE-2026-83335: Oracle Business Intelligence Enterprise Edition remote authentication bypass

CVE-2026-83335 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is an analytics and reporting platform used by enterprises to visualize and analyze business data. A vulnerability in the Analytics Server component allows a low-privileged attacker with network access to bypass authentication and gain administrative control over the entire system, potentially exposing sensitive business data and enabling malicious modifications to reports and analytics.

Technical details

This vulnerability in Oracle Business Intelligence Enterprise Edition's Analytics Server component is exploitable by a low-privileged network attacker without requiring user interaction. The attack vector is HTTP and can result in complete system compromise, granting the attacker confidentiality, integrity, and availability impacts. The vulnerability affects versions 8.2.0.0.0 and 26.01.0.0.0. The exact technical nature of the flaw is not disclosed in available references, but the high CVSS score and authentication bypass profile suggest it may involve privilege escalation or session handling flaws in the web interface.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats