ZeroHour

CVE-2026-83301

moderate

Low-Privilege Takeover Flaw in Oracle BI Enterprise Edition 12.2.1.4.0 Admin UI

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83301 is an easily exploitable vulnerability in the Service Administration UI of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics, affecting version 12.2.1.4.0. A remote attacker who already has a low-privileged (authenticated) account and network access via HTTP can trigger the flaw to fully compromise the OBIEE installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Any organization running the affected 12.2.1.4.0 release, especially where the analytics or administration consoles are reachable over the network, is exposed. There is no known public proof-of-concept, the issue is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported. Because exploitation requires only low privileges and no user interaction, it should still be treated as a high-priority patch for OBIEE deployments.

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-83301 to all OBIEE 12.2.1.4.0 instances as soon as it is available. Restrict network access to the Service Administration UI and analytics consoles (VPN/IP allowlisting, WAF rules) and ensure they are not internet-facing. Review low-privileged BI user accounts for anomalous logins or privilege changes and rotate credentials on affected systems.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Service Administration UI)
Estimated exposure
moderate≈ low thousands of internet-exposed OBIEE consoles; total enterprise install base likely in the tens of thousands — OBIEE is an on-premises enterprise analytics suite typically deployed inside corporate networks, with public internet scans historically showing a few thousand exposed Oracle BI/analytics consoles worldwide; the true reachable population…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Service Administration UI). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.