CVE-2026-83291
moderateLocal Privilege Escalation to Full Takeover in Oracle BI Enterprise Edition
CVE-2026-83291 is a vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (part of Oracle Analytics), affecting versions 8.2.0.0.0 and 26.01.0.0.0. It is easily exploitable by a low-privileged attacker who already has logon access to the server or infrastructure where OBIEE executes — for example, a local OS user or a low-privilege application account on the same host. Successful exploitation allows the attacker to fully compromise the OBIEE deployment, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, attack vector local). Because the attack vector is local, the vulnerable surface is the server infrastructure hosting OBIEE rather than the analytics end-user web interface. There is no known public proof of concept and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation in the wild is not indicated.
What to do: Apply the Oracle Critical Patch Update fixes covering CVE-2026-83291 to OBIEE 8.2.0.0.0 and 26.01.0.0.0 deployments as soon as the relevant CPU is available. In the interim, restrict and audit local OS and low-privilege accounts on hosts running OBIEE, enforce least privilege, and monitor those servers for privilege-escalation or unauthorized configuration-change activity.
| Oracle Business Intelligence Enterprise Edition (Oracle Analytics) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.