ZeroHour

CVE-2026-83289

moderate

Low-Privilege Takeover via SOAP in Oracle BI Enterprise Edition

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83289 is a difficult-to-exploit vulnerability in the Analytics Web General component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics. An authenticated, low-privileged attacker with network access to the product's SOAP interface can exploit the flaw, and a successful attack results in a complete takeover of the OBIEE installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). The high attack complexity (AC:H) and requirement for at least low-level credentials make opportunistic attacks less likely, but any attacker with a valid low-privilege account and network reachability to the SOAP endpoints is a plausible threat. Affected deployments are on-premises enterprise BI environments running versions 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update fixes for the Analytics Web General component on all affected versions (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0). Restrict network access to OBIEE SOAP endpoints to trusted internal users and VPN clients, and review low-privileged account activity for anomalous SOAP requests. Monitor Oracle's CPU advisory for this CVE and verify patch levels across all analytics servers in the environment.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Analytics Web General)
Estimated exposure
moderate≈1,000–5,000 internet-exposed instances, with a larger internal-only install base — OBIEE is enterprise on-premises BI software typically deployed behind corporate firewalls; internet-wide scans historically show only low thousands of exposed OBIEE analytics web/SOAP endpoints, while most installations are internal.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.