ZeroHour

CVE-2026-83323

niche

Local Privilege Escalation in Oracle BI Enterprise Edition 26.1 Platform Security

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83323 is a difficult-to-exploit flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE) release 26.01.0.0.0. A low-privileged attacker who already has logon access to the server or infrastructure hosting OBIEE, and who can trick a legitimate user into interacting (e.g., via social engineering), can escalate to a full takeover of the OBIEE deployment. Because the vulnerability changes scope, a successful attack may also significantly compromise other products running on the same environment beyond OBIEE itself, with high impacts to confidentiality, integrity, and availability (CVSS 3.1: 7.5). Only organizations running the affected 26.01.0.0.0 release are exposed, and exploitation requires local foothold plus human interaction, making opportunistic remote attacks unlikely. There is no known public proof of concept and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Apply the fix from Oracle's next Critical Patch Update as soon as it is available, since only release 26.01.0.0.0 is affected. Restrict interactive OS logon and low-privileged accounts on hosts running OBIEE, and apply least-privilege hardening there. Because successful exploitation requires user interaction, remind admins and BI users not to open unexpected content or approve actions on analytics hosts.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)26.01.0.0.0
Estimated exposure
nichelikely hundreds to low thousands of instances (only the very new 26.1 release is affected) — OBIEE is deployed at thousands of enterprises worldwide, but exposure is limited to installations on the newly released version 26.01.0.0.0, and no public install counts or scan data exist for this specific release.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.