ZeroHour

CVE-2026-83316

Difficult-to-Exploit Local Takeover Flaw in Oracle BI Enterprise Edition 26.01

CVSS 3.1
7.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83316 is a vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics, affecting supported version 26.01.0.0.0. The flaw is rated CVSS 3.1 7.0 (high) but is difficult to exploit and requires a local attack vector: a low-privileged attacker must already have logon access to the infrastructure (server/host) where OBIEE executes, meaning there is no unauthenticated or remote-only attack path. Successful exploitation allows the attacker to fully compromise the OBIEE installation, with high impact on confidentiality, integrity, and availability (complete product takeover). Organizations running OBIEE release 26.01.0.0.0 are the affected population, with practical risk concentrated on hosts shared with other local users or where OS-level access is loosely controlled. There is no known public proof of concept, the CVE is not on CISA's KEV list, and no in-the-wild exploitation has been reported as of this analysis (disclosed via Oracle's Critical Patch Update process).

What to do: Apply the Oracle Critical Patch Update patch for CVE-2026-83316 to OBIEE 26.01.0.0.0 as soon as your change window allows. Because exploitation requires local logon to the OBIEE host, enforce least-privilege OS account access on OBIEE servers, audit local accounts and shell access, and monitor for anomalous local processes or configuration changes on those systems.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)
Estimated exposure
unknown — plausibly thousands of enterprise OBIEE deployments, but not publicly enumerable — Oracle does not publish OBIEE installation counts and instances are typically internal, employee-facing enterprise deployments rather than internet-exposed services, so there is no reliable public scan or install-count basis for a figure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.