ZeroHour

CVE-2026-83324

moderate

Data integrity flaw in Oracle BI Enterprise Edition (BI Platform Security component)

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83324 is a difficult-to-exploit vulnerability in the BI Platform Security component of Oracle Business Intelligence Enterprise Edition (part of Oracle Analytics). A low-privileged attacker with network access via HTTP who successfully exploits the flaw can gain unauthorized creation, deletion, or modification access to critical data or all OBIEE-accessible data, as well as unauthorized read access to a subset of that data. Because the vulnerability has a scope change, successful attacks may also significantly impact additional products beyond OBIEE itself. Affected deployments are those running versions 8.2.0.0.0 or 26.01.0.0.0. No public proof-of-concept is known and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so there is no indication of in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-83324 for versions 8.2.0.0.0 and 26.01.0.0.0 as soon as your change window allows. Restrict HTTP access to OBIEE consoles to trusted networks/VPNs and enforce least-privilege role assignments, since exploitation requires an authenticated low-privileged account. Review audit logs for unexpected data creation, deletion, or modification by low-privilege BI users and for any suspicious cross-product impact, given the scope change.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics)8.2.0.0.0, 26.01.0.0.0
Estimated exposure
moderate≈ low thousands of internet-reachable OBIEE consoles; larger but uncounted internal enterprise deployments — OBIEE is enterprise on-premises software typically deployed at mid-size and large organizations, and public internet scans historically show only a few thousand exposed Oracle Analytics/BI login consoles, so the internet-exposed population…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.