ZeroHour

CVE-2026-83293

moderate

Local Privilege Escalation in Oracle BI Enterprise Edition 12.2.1.4.0

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

A local privilege escalation vulnerability exists in the FNDN component of Oracle Business Intelligence Enterprise Edition (OBIEE) 12.2.1.4.0, part of Oracle Analytics. It is easily exploitable by a low-privileged attacker who already has logon access to the host or infrastructure where OBIEE executes, requiring no user interaction. Successful exploitation allows the attacker to fully compromise the OBIEE deployment, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). Any organization running the affected 12.2.1.4.0 release of OBIEE is exposed, primarily through local accounts or lateral movement on BI server infrastructure. No public proof of concept is known and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating no observed in-the-wild exploitation to date.

What to do: Apply the Oracle Critical Patch Update that remedies CVE-2026-83293 to all OBIEE 12.2.1.4.0 installations. Restrict and audit local OS accounts on BI middleware hosts, enforce least privilege, and monitor for unexpected privilege elevation or process execution under the BI service accounts. Verify that development, test, and disaster-recovery instances are patched as well, since local-access flaws affect every tier, not just production.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)
Estimated exposure
moderatelikely thousands of enterprise deployments worldwide (order of magnitude: ~1,000–10,000 installations) — OBIEE is on-premises enterprise analytics software deployed by mid-size and large organizations rather than internet-exposed consumer systems, and no public install counts or scan data were available, so this is a rough estimate based on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: FNDN). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.