ZeroHour

CVE-2026-83294

moderate

Unauthenticated Local Takeover Flaw in Oracle BI Enterprise Edition

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83294 is a high-severity (CVSS 7.8) flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. An unauthenticated attacker who already has logon access to the server or infrastructure hosting OBIEE can exploit this easily, but the attack requires human interaction from a person other than the attacker — most plausibly tricking a legitimate user on the system into performing an action (e.g., opening a malicious file or link) that triggers the compromise. A successful attack can result in a full takeover of OBIEE, with high impact on the confidentiality, integrity, and availability of the analytics platform and the business data it holds. Organizations running the listed OBIEE versions on shared or multi-user infrastructure are primarily at risk, since the attack vector is local rather than remote/network. The flaw is not listed in CISA's KEV catalog and no public proof-of-concept is known, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83294 to all OBIEE 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 installations. Restrict OS-level logon access to OBIEE hosts to only necessary administrators and service accounts, since the attack requires local presence plus user interaction. Brief users with access to these servers to avoid opening untrusted files or links, and review authentication and audit logs on affected hosts for anomalous activity.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)
Estimated exposure
moderateon the order of thousands to tens of thousands of enterprise OBIEE servers worldwide — OBIEE is licensed enterprise analytics software deployed on-premises at mid-size and large organizations (typically one to a handful of instances per customer), and instances are rarely internet-exposed, so the vulnerable population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.