CVE-2026-83325
moderateHigh-Privilege Takeover Flaw in Oracle BI Enterprise Edition Platform Security
CVE-2026-83325 is a vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of Oracle Analytics, affecting versions 8.2.0.0.0 and 26.01.0.0.0. It is easily exploitable by a high-privileged attacker who has network access to the OBIEE server over HTTP, requiring no user interaction. A successful attack allows the attacker to fully compromise the OBIEE installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). Because exploitation requires high privileges, the realistic threat is a malicious or compromised administrative insider, or an external attacker who has already obtained admin credentials through phishing or credential theft. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no evidence of active exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83325 for your affected release (8.2.0.0.0 or 26.01.0.0.0) as soon as it is available. Restrict HTTP(S) access to OBIEE administration and analytics endpoints to trusted networks or VPN, and ensure admin consoles are not internet-facing. Review high-privileged BI accounts for legitimacy, enforce MFA where possible, and audit logs for anomalous activity by privileged users.
| Oracle Business Intelligence Enterprise Edition (Oracle Analytics) | 8.2.0.0.0 |
| Oracle Business Intelligence Enterprise Edition (Oracle Analytics) | 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.