ZeroHour

CVE-2026-83288

moderate

Local Privilege Escalation to Full Takeover in Oracle BI Enterprise Edition (BI Search)

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83288 is a local privilege escalation flaw in the BI Search component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics. It is exploited by an attacker who already holds a low-privileged logon on the infrastructure (host) where OBIEE executes; Oracle rates it as easily exploitable, requiring low privileges and no user interaction (CVSS 3.1 base 7.8, AV:L/PR:L). Successful attacks allow complete takeover of the OBIEE deployment, with high impact on confidentiality, integrity, and availability. Affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. There is no known public proof-of-concept and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83288 to every OBIEE installation running version 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0, prioritizing hosts shared by multiple users or service accounts. Since exploitation requires only a low-privileged local logon, restrict OS-level accounts on BI servers to trusted administrators and apply least privilege. Review BI server logs for unexpected privilege escalation, new account creation, or configuration changes to BI Search components.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, BI Search component)
Estimated exposure
moderateLikely low thousands to tens of thousands of on-premises OBIEE deployments worldwide (estimate) — OBIEE is enterprise analytics software run on internal servers at mid-to-large organizations, with no public install counts and only a few thousand internet-exposed consoles seen in public scans, and this flaw's local attack vector means…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.