ZeroHour

CVE-2026-83071

moderate

Local Privilege Escalation to Full Takeover in Oracle BI Enterprise Edition

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83071 is a high-severity flaw (CVSS 3.1: 7.8) in the Machine Learning component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics, affecting versions 8.2.0.0.0 and 26.01.0.0.0. It is easily exploitable by a low-privileged attacker who already has a logon on the server or infrastructure where OBIEE executes — the attack vector is local, with low complexity, low privileges required, and no user interaction. Successful exploitation allows the attacker to fully compromise the OBIEE deployment, with high impact on confidentiality, integrity, and availability — effectively a complete takeover of the platform. Because exploitation requires existing local access, the risk is concentrated in environments where untrusted or broadly shared OS accounts can reach BI infrastructure. The flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no evidence of exploitation in the wild.

What to do: Apply Oracle's Critical Patch Update remediation for CVE-2026-83071 to all OBIEE instances running versions 8.2.0.0.0 or 26.01.0.0.0. Enforce least privilege and tightly restrict or audit local OS accounts on servers hosting OBIEE, since the flaw is exploitable only by users with logon to that infrastructure. Investigate any history of low-privileged accounts elevating privileges or accessing BI data unexpectedly on affected hosts.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, Machine Learning component)
Estimated exposure
moderatelikely low thousands of enterprise OBIEE deployments worldwide (no public install counts) — OBIEE/OAS is a legacy-major on-premises enterprise BI platform typically deployed at mid-to-large organizations, implying thousands of instances, but no active-install or scan counts were provided; also note the local attack vector limits…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Machine Learning). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.