CVE-2026-83282

9.9

Oracle · Business Intelligence Enterprise Edition

A critical vulnerability in Oracle Business Intelligence Enterprise Edition allows a low-privileged, network-based attacker to achieve full system takeover via HTTP.

Executive summary

A critical vulnerability in Oracle Business Intelligence Enterprise Edition, version 12.2.1.4.0, allows for total system compromise by a low-privileged attacker.

Vulnerability

This flaw exists within the Platform Security component and is easily exploitable over a network connection. An attacker with low-level privileges can trigger this vulnerability via HTTP to gain full control over the application, with the potential for impact across the broader infrastructure due to a change in scope.

Business impact

The CVSS score of 9.9 reflects the extreme severity of this flaw, as it allows for the complete takeover of a critical business intelligence platform. Successful exploitation could lead to total loss of confidentiality, integrity, and availability of sensitive corporate data, potentially resulting in unauthorized access to connected systems and significant operational disruption.

Remediation

Immediate Action: Review the official Oracle security advisory at https://www.oracle.com/security-alerts/cspusep2026.html to identify the required patch or mitigation steps for version 12.2.1.4.0.

Proactive Monitoring: Audit access logs for suspicious HTTP requests targeting the Platform Security component and monitor for unauthorized administrative actions or unexpected system configuration changes.

Compensating Controls: Implement strict network segmentation to restrict access to the BI platform and deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious HTTP payloads directed at this service.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical severity and the potential for complete system takeover, organizations must treat this vulnerability with the highest priority. Security teams should immediately verify if their environment is running version 12.2.1.4.0 and apply all vendor-supplied patches as soon as they are made available to prevent unauthorized access and potential lateral movement within the network.

More Oracle CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources