CVE-2026-83301
8.8Oracle · Oracle Business Intelligence Enterprise Edition
A vulnerability in the Oracle Business Intelligence Enterprise Edition Service Administration UI allows low-privileged network attackers to achieve a full system takeover.
Executive summary
A critical vulnerability in Oracle Business Intelligence Enterprise Edition allows authenticated attackers to gain full control of the application, presenting a significant risk to organizational data integrity.
Vulnerability
This vulnerability exists within the Service Administration UI component and is reachable via HTTP by any low-privileged authenticated user. The flaw allows an attacker to bypass intended restrictions and achieve a complete takeover of the affected instance.
Business impact
Successful exploitation of this vulnerability results in the total compromise of the Oracle Business Intelligence platform, granting attackers full control over administrative functions. Given the CVSS 3.1 base score of 8.8, this represents a high-severity risk that could lead to unauthorized access to sensitive business intelligence data, potential lateral movement within the network, and complete loss of system availability.
Remediation
Immediate Action: Review the official Oracle security advisory for the latest CPU (Critical Patch Update) and apply the necessary patches to version 12.2.1.4.0 or higher immediately.
Proactive Monitoring: Monitor Service Administration UI access logs for unusual administrative activity or requests originating from non-administrative user accounts.
Compensating Controls: Implement strict network segmentation to limit access to the administration interface and deploy Web Application Firewall rules to detect and block unauthorized attempts to interact with the service administration endpoints.
Exploitation status
Public Exploit Available: No — no confirmed public exploit exists.
Analyst recommendation
This vulnerability poses a severe threat due to the potential for total system takeover. Administrators should prioritize the identification of all instances running version 12.2.1.4.0 and apply vendor-supplied patches as soon as they become available. Until patching is completed, restricting network access to the administration console is strongly advised to mitigate the attack surface.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Oracle Advisory Vendor advisory