ZeroHour

CVE-2026-83299

moderate

Unauthenticated Takeover Flaw in Oracle BI Enterprise Edition 12.2.1.4.0

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83299 is a difficult-to-exploit vulnerability in the Analytics Web General component of Oracle Business Intelligence Enterprise Edition (OBIEE) 12.2.1.4.0. An unauthenticated attacker with network access via HTTP can trigger the flaw to fully compromise the OBIEE server, with high impacts on confidentiality, integrity, and availability (CVSS 3.1: 8.1, vector AV:N/AC:H/PR:N/UI:N/S:U). The high attack-complexity rating means exploitation requires specialized conditions, but a successful attack results in complete product takeover. Organizations running the affected 12.2.1.4.0 release with the Analytics Web console reachable over the network are exposed, especially where the HTTP endpoint faces the internet. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83299 to all OBIEE 12.2.1.4.0 instances, prioritizing any with the Analytics Web HTTP endpoint internet-reachable. Restrict network access to the Analytics Web/console ports via firewall rules or VPN so only trusted users and subnets can connect. Review web-server and BI logs for unexplained unauthenticated HTTP requests targeting the Analytics Web component as an indicator of attempted exploitation.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Analytics Web General)
Estimated exposure
moderate≈ low thousands of internet-exposed OBIEE web consoles, with a larger population of internal-only deployments (likely tens of thousands of installs total) —… — OBIEE is a licensed enterprise analytics suite, and public internet-wide scans (e.g., Shodan/Censys) typically show only a few thousand exposed OBIEE/Analytics Web consoles, since most deployments sit behind corporate firewalls.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.