ZeroHour

CVE-2026-83286

moderate

Unauthenticated Takeover Flaw in Oracle BI Enterprise Edition Platform Security

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83286 is a difficult-to-exploit vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics. It allows an unauthenticated remote attacker with network access via HTTP to compromise the affected OBIEE installation, and successful attacks can result in a complete takeover of the product, with high impacts on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, which are commonly deployed in mid-to-large enterprises for on-premises reporting and analytics. The high attack complexity (AC:H) means exploitation requires specialized conditions, which lowers practical risk relative to the base score. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83286 to all affected OBIEE 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 installations as soon as the relevant patch is available for your release line. Restrict HTTP access to analytics consoles and admin endpoints via firewall rules or network segmentation so they are not reachable from untrusted networks. Review logs for unauthenticated HTTP requests to the analytics platform and monitor for unauthorized account or configuration changes that would indicate a takeover attempt.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)8.2.0.0.0
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)12.2.1.4.0
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)26.01.0.0.0
Estimated exposure
moderate≈low thousands of internet-exposed OBIEE consoles, plus a larger internal-only enterprise install base — OBIEE is enterprise on-premises BI middleware; public internet scans (Shodan/Censys-type) historically find low thousands of exposed analytics consoles globally, while the majority of deployments sit on internal networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.