ZeroHour

CVE-2026-83290

large

Local Privilege Escalation in Oracle Business Intelligence Enterprise Edition

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83290 is a vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics, affecting versions 8.2.0.0.0 and 26.01.0.0.0. The flaw is easily exploitable by a low-privileged attacker who already has logon access to the host where OBIEE executes (attack vector: local), requiring no user interaction. A successful attack allows the attacker to compromise the entire OBIEE deployment, with high impact on confidentiality, integrity, and availability — effectively a takeover of the platform (CVSS 3.1 base score 7.8). Organizations running the affected on-premises versions with multiple local OS or application accounts on BI servers are the primary concern. No public proof-of-concept exists and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.

What to do: Apply the Oracle Critical Patch Update that remedies this issue to OBIEE 8.2.0.0.0 and 26.01.0.0.0 environments, prioritizing hosts with many local or interactive accounts. Restrict and audit local OS accounts on BI servers, and review privilege boundaries between low-privileged users and the OBIEE runtime. Check for signs of unauthorized local account activity or unexpected elevation on affected servers.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)8.2.0.0.0, 26.01.0.0.0
Estimated exposure
largetens of thousands of enterprise deployments worldwide, with a few thousand internet-exposed OBIEE consoles seen in public scans — OBIEE is a widely deployed on-premises enterprise BI suite; because this is a local-vector flaw, every installation with multiple local accounts is relevant, and public internet scans have historically shown thousands of reachable OBIEE…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.