CVE-2026-83283
moderateUnauthenticated Takeover Flaw in Oracle BI Enterprise Edition 12.2.1.4.0
CVE-2026-83283 is a critical (CVSS 9.8) flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), affecting version 12.2.1.4.0. It is triggered remotely over HTTP by an attacker with no credentials and no user interaction, requiring only network reachability to the OBIEE service. A successful exploit allows complete takeover of the OBIEE installation, with high impact on confidentiality, integrity, and availability — including access to sensitive analytics data, reports, and potentially connected backend data sources. Organizations running the affected 12.2.1.4.0 release, especially those with OBIEE consoles reachable from untrusted networks, are at risk. There is no known public proof of concept and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83283 to all OBIEE 12.2.1.4.0 installations as soon as possible; since 12.2.1.4.0 is the terminal OBIEE release, also plan migration to Oracle Analytics Server for continued security support. Restrict HTTP/HTTPS access to OBIEE consoles via firewall rules or VPN so they are not reachable from untrusted networks. Review BI service accounts, administrative users, and audit logs for signs of unauthorized access following patching.
| Oracle Business Intelligence Enterprise Edition (Oracle Analytics) | 12.2.1.4.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.