ZeroHour

CVE-2026-83321

moderate

Privilege Escalation in Oracle BI Enterprise Edition Analytics Actions

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

A high-severity (CVSS 3.1: 8.5) vulnerability in the Analytics Actions component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics, allows a low-privileged authenticated attacker with network access via HTTP to compromise the product. Exploitation is described by Oracle as easy, and because the flaw changes scope, a successful attack may also significantly impact additional products beyond OBIEE itself. The impact is unauthorized access to critical data or complete access to all OBIEE-accessible data, plus unauthorized update, insert, or delete access to some of that data; availability is not affected. Affected deployments are those running version 8.2.0.0.0 or 26.01.0.0.0. There is no known public proof of concept and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that addresses this flaw to all OBIEE instances on 8.2.0.0.0 or 26.01.0.0.0. Restrict HTTP access to OBIEE consoles so they are not internet-facing, and enforce least-privilege roles for low-privileged BI accounts. Review audit logs for anomalous data reads or unexpected insert/update/delete activity by low-privilege users, and check whether other products integrated with OBIEE were reachable in the event of scope change.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Analytics Actions)8.2.0.0.0, 26.01.0.0.0
Estimated exposure
moderatelikely a few thousand internet-reachable OBIEE consoles, with total enterprise deployments (internal and external) plausibly in the tens of thousands — clearly… — OBIEE is enterprise on-premises analytics software, and public internet scans (e.g., Shodan/Censys) typically show only low-thousands of exposed Oracle BI consoles, while the majority of instances sit on internal networks with large but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Actions). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.