ZeroHour

CVE-2026-83296

moderate

Low-Privilege Takeover Flaw in Oracle BI Enterprise Edition BI Search Component

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83296 is a difficult-to-exploit vulnerability in the BI Search component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics. A remote attacker who already holds low-privileged credentials and has HTTP network access to the OBIEE server can trigger the flaw, and a successful attack results in a full takeover of the OBIEE installation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.5, AV:N/AC:H/PR:L/UI:N/S:U). The affected releases are versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Exploitation status: no public proof-of-concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and there are no reports of in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83296 to all OBIEE instances running versions 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Verify that BI Search and analytics consoles are not exposed to untrusted networks, and restrict low-privileged BI user accounts to least-privilege roles. Review authentication and audit logs for anomalous activity by low-privilege accounts against the BI Search component.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)
Estimated exposure
moderate≈ low thousands of internet-exposed OBIEE consoles; likely tens of thousands of total enterprise deployments (estimate) — OBIEE is a widely deployed enterprise BI platform that is typically internal-facing, but public internet scans (e.g., Shodan/Censys) historically show a few thousand exposed OBIEE/Oracle Analytics login consoles; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.