ZeroHour

CVE-2026-83335

moderate

Low-Privilege Takeover Flaw in Oracle BI Enterprise Edition Analytics Server

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83335 is a high-severity flaw (CVSS 3.1: 8.8) in the Analytics Server component of Oracle Business Intelligence Enterprise Edition, affecting versions 8.2.0.0.0 and 26.01.0.0.0. It is described by Oracle as easily exploitable by a low-privileged (i.e., authenticated with minimal rights) attacker who has network access to the server over HTTP. Successful exploitation allows the attacker to fully take over the Oracle BI Enterprise Edition deployment, with high impact on the confidentiality, integrity, and availability of the platform and its data. Organizations running the affected on-premises Analytics Server releases are exposed wherever the service is reachable by low-trust users, and the risk is greatest for instances with HTTP endpoints exposed to broader networks. No public proof-of-concept exists, there is no evidence of in-the-wild exploitation, and the flaw is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83335 to all deployments of versions 8.2.0.0.0 and 26.01.0.0.0. Restrict HTTP access to Analytics Server endpoints (consoles and web services) to trusted networks or VPN, and verify no instances are unintentionally internet-facing. Review low-privileged BI account activity for anomalies and rotate credentials on systems where suspicious access is found.

Affected
Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Analytics Server)
Estimated exposure
moderatelikely thousands of enterprise deployments, with plausibly a few thousand internet-exposed Analytics Server instances — OBIEE/Analytics Server is enterprise on-premises BI software deployed at large organizations rather than consumers, and internet-wide scans of Oracle BI/Analytics consoles typically show only low thousands of exposed instances since most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.