CVE-2026-83317
largeLocal Privilege Escalation in Oracle BI Enterprise Edition Installation Component
CVE-2026-83317 is a flaw in the Installation component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics. It is easily exploitable by a low-privileged attacker who already has logon access to the operating system or infrastructure where OBIEE runs — no user interaction is required — and successful exploitation allows a full takeover of the OBIEE deployment with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). Because the attack vector is local (AV:L/PR:L), this is primarily an insider-threat or post-compromise privilege escalation risk rather than a remotely exploitable internet-facing flaw. Affected deployments include OBIEE versions 8.2.0.0.0, 12.2.1.4.0 (the long-standing on-premises release), and 26.01.0.0.0. No public proof-of-concept is known and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is no indication of active exploitation.
What to do: Apply the Oracle Critical Patch Update that addresses this vulnerability to OBIEE 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 as soon as patching windows allow. In the interim, minimize and audit local OS accounts and service accounts on servers hosting OBIEE, and restrict interactive shell or remote desktop access to that infrastructure to trusted administrators only. Review authentication and privilege-change logs on BI hosts for signs of low-privileged accounts escalating access.
| Oracle Business Intelligence Enterprise Edition (Oracle Analytics) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Installation). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.