ZeroHour

CVE-2026-83282

moderate

Low-Privilege Takeover Flaw in Oracle BI Enterprise Edition 12.2.1.4.0

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83282 is a critical vulnerability (CVSS 3.1 base score 9.9) in the Platform Security component of Oracle Business Intelligence Enterprise Edition 12.2.1.4.0, part of Oracle Analytics. A low-privileged, authenticated attacker with network access via HTTP can send crafted requests that compromise the OBIEE installation and, because the scope changes, may also significantly impact additional products beyond OBIEE itself. Successful exploitation results in a complete takeover of OBIEE with high impact on confidentiality, integrity, and availability, meaning an attacker could read, alter, or destroy business analytics data and pivot to connected systems. Organizations running the affected 12.2.1.4.0 release, especially instances reachable over a network, are at risk. As of now, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and no active exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83282 to your OBIEE 12.2.1.4.0 environment as soon as it is available. Restrict network access to OBIEE HTTP endpoints (VPNs, allowlists, WAF rules) so only trusted users can reach the platform, and audit low-privileged accounts for suspicious privilege changes or anomalous activity. Given the scope change, also review access and logs on integrated products that trust OBIEE credentials or share its infrastructure.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Platform Security)
Estimated exposure
moderate≈ low thousands of internet-exposed OBIEE instances; total on-prem install base plausibly in the tens of thousands (estimate) — OBIEE is on-premises enterprise software, and public internet scans (Shodan/FOFA-style) typically find only a few thousand exposed OBIEE consoles while most deployments sit on internal networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.