ZeroHour

CVE-2026-83295

moderate

Authenticated SOAP Flaw Enables Full Takeover in Oracle BI Enterprise Edition

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83295 is a difficult-to-exploit vulnerability in the Presentation Services component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics. It is triggered by a low-privileged authenticated attacker sending crafted requests to the product's SOAP interface over the network, and successful exploitation allows complete takeover of the OBIEE installation with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). Affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, which are widely deployed on-premises BI installations at mid-size and large organizations. The high attack complexity and requirement for valid low-privileged credentials reduce the likelihood of opportunistic attacks, and no public proof-of-concept or confirmed in-the-wild exploitation is known. The vulnerability is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83295 to all affected OBIEE installations on versions 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Restrict network access to OBIEE SOAP endpoints (and the product generally) to trusted internal users and VPN ranges, and audit low-privileged accounts for anomalous activity or unexpected privilege changes. Verify that BI Presentation Services consoles are not exposed to the public internet.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, Presentation Services)8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Estimated exposure
moderate≈ low thousands of internet-exposed OBIEE instances, plausibly tens of thousands of deployments overall — OBIEE is enterprise on-premises BI software where public internet scans historically show only low thousands of exposed login/SOAP endpoints, with the majority of deployments internal-facing behind corporate networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.