CVE-2026-83323
nicheLocal Privilege Escalation in Oracle BI Enterprise Edition 26.1 Platform Security
CVE-2026-83323 is a difficult-to-exploit flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE) release 26.01.0.0.0. A low-privileged attacker who already has logon access to the server or infrastructure hosting OBIEE, and who can trick a legitimate user into interacting (e.g., via social engineering), can escalate to a full takeover of the OBIEE deployment. Because the vulnerability changes scope, a successful attack may also significantly compromise other products running on the same environment beyond OBIEE itself, with high impacts to confidentiality, integrity, and availability (CVSS 3.1: 7.5). Only organizations running the affected 26.01.0.0.0 release are exposed, and exploitation requires local foothold plus human interaction, making opportunistic remote attacks unlikely. There is no known public proof of concept and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Apply the fix from Oracle's next Critical Patch Update as soon as it is available, since only release 26.01.0.0.0 is affected. Restrict interactive OS logon and low-privileged accounts on hosts running OBIEE, and apply least-privilege hardening there. Because successful exploitation requires user interaction, remind admins and BI users not to open unexpected content or approve actions on analytics hosts.
| Oracle Business Intelligence Enterprise Edition (Oracle Analytics) | 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.