ZeroHour

CVE-2026-83292

moderate

Authenticated Takeover of Oracle BI Enterprise Edition via Platform Security Flaw

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83292 is a vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics, affecting versions 8.2.0.0.0 and 26.01.0.0.0. A low-privileged attacker with network access via HTTP who already holds valid credentials can exploit the flaw — rated difficult due to high attack complexity (CVSS 3.1: 7.5, AV:N/AC:H/PR:L/UI:N) — to fully compromise the OBIEE installation. A successful attack results in a complete takeover of the product, with high impact on confidentiality, integrity, and availability, exposing sensitive BI reports, dashboards, and underlying data connections. Organizations running the affected on-premises or private-cloud OBIEE deployments with HTTP-accessible consoles and multiple user accounts are exposed, and exploitation is made easier by any external exposure of the login pages. No public proof-of-concept exists and the CVE is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring in the wild.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83292 to all OBIEE 8.2.0.0.0 and 26.01.0.0.0 installations as soon as it is available. Restrict HTTP/HTTPS access to BI consoles and analytics endpoints to trusted networks or VPN, enforce least-privilege role assignments for low-privileged accounts, and audit authentication and administrative-action logs for anomalous activity by low-privilege users.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Platform Security)8.2.0.0.0, 26.01.0.0.0
Estimated exposure
moderatelikely thousands of enterprise installations globally, with only a small fraction (likely low thousands) internet-exposed — OBIEE is on-premises enterprise analytics software with no public install counts, but public internet scans historically show only a few thousand exposed OBIEE/OAS consoles because most deployments are internal-facing; the majority of the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.