CVE-2026-83287
moderateAuthenticated SOAP Data Disclosure in Oracle Business Intelligence Enterprise Edition
CVE-2026-83287 is a vulnerability in the Presentation Services component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics. A low-privileged (authenticated) attacker with network access to the product's SOAP interface can exploit the flaw easily and, because of a scope change, may gain unauthorized access to critical data or complete access to all data reachable through the affected OBIEE deployment, potentially including data from additional products. Only confidentiality is impacted (no integrity or availability impact per the CVSS vector), but the scope change means data beyond OBIEE itself could be exposed. Affected deployments are those running versions 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0 that expose SOAP services to low-privilege users. No public proof of concept is known and the flaw is not on the CISA KEV list, indicating no observed in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83287 to all OBIEE instances on 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Restrict network access to SOAP/Presentation Services endpoints so only trusted users and networks can reach them, and review which low-privilege accounts can authenticate to those endpoints. Audit logs for anomalous data access by low-privilege accounts, given the scope-change potential for exposure of data in connected products.
| Oracle Business Intelligence Enterprise Edition (Oracle Analytics) | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.