ZeroHour

CVE-2026-83322

moderate

Privileged HTTP Takeover Flaw in Oracle Business Intelligence Enterprise Edition

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

An easily exploitable vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (part of Oracle Analytics) allows a high-privileged attacker with network access via HTTP to fully compromise the BI platform. Exploitation requires valid high-privileged credentials or a compromised administrator account, sending crafted requests to the product's HTTP interface. A successful attack results in complete takeover of Oracle BI EE with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.2). Affected installations are versions 8.2.0.0.0 and 26.01.0.0.0; no public PoC is known and the flaw is not listed in CISA's KEV, so exploitation is not currently observed.

What to do: Apply Oracle's Critical Patch Update (CPU) remediation for this CVE to all instances of OBIEE 8.2.0.0.0 and 26.01.0.0.0 as soon as it is available. Restrict HTTP access to the BI platform and its administrative interfaces to trusted networks or VPN, and enforce MFA and least-privilege for high-privileged BI accounts. Audit privileged users and review logs on affected hosts for anomalous activity indicative of misuse of this flaw.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Platform Security)8.2.0.0.0, 26.01.0.0.0
Estimated exposure
moderateplausibly low thousands of internet-exposed OBIEE consoles out of a larger enterprise on-prem installed base (order of magnitude: thousands) — OBIEE is on-premises enterprise software typically deployed at mid-to-large organizations with only a fraction of consoles internet-facing per common public scan patterns; no vendor-published install counts exist, so this is a rough…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.