ZeroHour

CVE-2026-83317

large

Local Privilege Escalation in Oracle BI Enterprise Edition Installation Component

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83317 is a flaw in the Installation component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics. It is easily exploitable by a low-privileged attacker who already has logon access to the operating system or infrastructure where OBIEE runs — no user interaction is required — and successful exploitation allows a full takeover of the OBIEE deployment with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). Because the attack vector is local (AV:L/PR:L), this is primarily an insider-threat or post-compromise privilege escalation risk rather than a remotely exploitable internet-facing flaw. Affected deployments include OBIEE versions 8.2.0.0.0, 12.2.1.4.0 (the long-standing on-premises release), and 26.01.0.0.0. No public proof-of-concept is known and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is no indication of active exploitation.

What to do: Apply the Oracle Critical Patch Update that addresses this vulnerability to OBIEE 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 as soon as patching windows allow. In the interim, minimize and audit local OS accounts and service accounts on servers hosting OBIEE, and restrict interactive shell or remote desktop access to that infrastructure to trusted administrators only. Review authentication and privilege-change logs on BI hosts for signs of low-privileged accounts escalating access.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)
Estimated exposure
large≈tens of thousands of enterprise server installations worldwide (estimated) — OBIEE is on-premises enterprise analytics middleware deployed by mid-sized and large organizations globally, with 12.2.1.4.0 being a long-lived, widely installed release; because exploitation requires local logon, only servers hosting…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Installation). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.