ZeroHour

CVE-2026-83273

moderate

High-Privilege Takeover Flaw in Oracle BI Enterprise Edition Platform Security

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83273 is a vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics, affecting supported version 26.01.0.0.0. It is easily exploitable by an attacker who already holds high privileges and has network access to the OBIEE server via HTTP, allowing them to fully compromise the product. A successful attack results in complete takeover of the OBIEE installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). Organizations running the affected version are exposed, particularly if the OBIEE console or related HTTP endpoints are reachable by untrusted or semi-trusted users, since any compromised high-privileged account (for example through credential theft or insider misuse) becomes a path to full system takeover. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no active exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses this issue to all OBIEE 26.01.0.0.0 installations as soon as it is available. Restrict HTTP access to OBIEE consoles and analytics endpoints via firewall rules, reverse proxies, or VPN so only trusted administrators can reach them, and enforce least-privilege role assignments to limit who holds the high privileges required for exploitation. Finally, audit high-privileged OBIEE accounts and review access logs for anomalous activity indicative of credential misuse.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)26.01.0.0.0
Estimated exposure
moderate≈ low thousands of internet-reachable OBIEE instances, plus a larger unseen population of intranet deployments on the affected 26.01 release (order 10^3–10^4… — OBIEE is enterprise on-premises analytics software deployed at mid-to-large organizations, and public internet scans historically show only a few thousand exposed OBIEE consoles, with most deployments internal — and only the subset running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.