ZeroHour

CVE-2026-83270

moderate

Unauthenticated Data Disclosure in Oracle Business Intelligence Enterprise Edition

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83270 is a vulnerability in the BI Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), affecting supported versions 8.2.0.0.0 and 26.01.0.0.0. It is easily exploitable by an unauthenticated attacker with network access over HTTP, requiring no privileges and no user interaction. A successful attack results in unauthorized access to critical data or complete read access to all data accessible through the OBIEE deployment — a serious exposure for BI platforms, which typically aggregate sensitive reporting, financial, and customer data from across an organization. Because the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) shows confidentiality-only impact, attackers can read data but cannot modify it or crash the service. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently unknown/none known.

What to do: Apply Oracle's Critical Patch Update that remediates CVE-2026-83270 to deployments on 8.2.0.0.0 or 26.01.0.0.0 as soon as it is available. Restrict HTTP access to OBIEE analytics consoles (including default BI/BI Platform Security endpoints) to trusted networks or VPN rather than exposing them to the internet. Review access logs on affected instances for unauthenticated requests reaching the BI Platform Security component that could indicate probing or data theft.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)8.2.0.0.0
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)26.01.0.0.0
Estimated exposure
moderate≈ low-thousands of internet-exposed OBIEE consoles, plus a larger uncounted base of internal-only deployments — OBIEE is on-premises/enterprise analytics middleware, and public internet scans (e.g., Shodan/Censys for exposed OBIEE/Oracle Analytics consoles on their default HTTP ports) typically surface on the order of a few thousand instances, while…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.