CVE-2026-83292
moderateAuthenticated Takeover of Oracle BI Enterprise Edition via Platform Security Flaw
CVE-2026-83292 is a vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics, affecting versions 8.2.0.0.0 and 26.01.0.0.0. A low-privileged attacker with network access via HTTP who already holds valid credentials can exploit the flaw — rated difficult due to high attack complexity (CVSS 3.1: 7.5, AV:N/AC:H/PR:L/UI:N) — to fully compromise the OBIEE installation. A successful attack results in a complete takeover of the product, with high impact on confidentiality, integrity, and availability, exposing sensitive BI reports, dashboards, and underlying data connections. Organizations running the affected on-premises or private-cloud OBIEE deployments with HTTP-accessible consoles and multiple user accounts are exposed, and exploitation is made easier by any external exposure of the login pages. No public proof-of-concept exists and the CVE is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring in the wild.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83292 to all OBIEE 8.2.0.0.0 and 26.01.0.0.0 installations as soon as it is available. Restrict HTTP/HTTPS access to BI consoles and analytics endpoints to trusted networks or VPN, enforce least-privilege role assignments for low-privileged accounts, and audit authentication and administrative-action logs for anomalous activity by low-privilege users.
| Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Platform Security) | 8.2.0.0.0, 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.