ZeroHour

CVE-2026-83287

moderate

Authenticated SOAP Data Disclosure in Oracle Business Intelligence Enterprise Edition

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83287 is a vulnerability in the Presentation Services component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics. A low-privileged (authenticated) attacker with network access to the product's SOAP interface can exploit the flaw easily and, because of a scope change, may gain unauthorized access to critical data or complete access to all data reachable through the affected OBIEE deployment, potentially including data from additional products. Only confidentiality is impacted (no integrity or availability impact per the CVSS vector), but the scope change means data beyond OBIEE itself could be exposed. Affected deployments are those running versions 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0 that expose SOAP services to low-privilege users. No public proof of concept is known and the flaw is not on the CISA KEV list, indicating no observed in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83287 to all OBIEE instances on 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Restrict network access to SOAP/Presentation Services endpoints so only trusted users and networks can reach them, and review which low-privilege accounts can authenticate to those endpoints. Audit logs for anomalous data access by low-privilege accounts, given the scope-change potential for exposure of data in connected products.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Estimated exposure
moderate≈ low thousands of internet-exposed OBIEE/Presentation Services servers, out of a larger (tens of thousands) global enterprise install base — OBIEE is on-premises enterprise analytics software; public internet scans (e.g., Shodan/Censys) have historically shown a few thousand exposed OBIEE consoles and SOAP endpoints, while most deployments sit on internal networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.