CVE-2026-83336
moderateLocal Privilege Escalation to Full Takeover in Oracle BI Enterprise Edition Analytics Server
CVE-2026-83336 is a high-severity (CVSS 3.1: 7.8) local privilege escalation flaw in the Analytics Server component of Oracle Business Intelligence Enterprise Edition, affecting versions 8.2.0.0.0 and 26.01.0.0.0. It is easily exploitable by a low-privileged attacker who already has logon access to the host or infrastructure where OBIEE runs, requiring no user interaction. A successful attack allows the attacker to fully compromise the OBIEE deployment, with high impact on confidentiality, integrity, and availability — effectively a takeover of the platform and its BI data. Organizations running the affected on-prem Analytics Server versions are exposed primarily from insiders, compromised low-privilege accounts, or attackers who have gained a foothold on the server. The flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof of concept is known, so exploitation is presumed limited at this time.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83336 to OBIEE Analytics Server installations on 8.2.0.0.0 or 26.01.0.0.0 as soon as it is available for your release train. Minimize and audit local OS accounts on BI server hosts, enforce least privilege, and monitor for privilege escalation or unexpected process activity by low-privileged users on servers running Analytics Server.
| Oracle Business Intelligence Enterprise Edition (Analytics Server component) | 8.2.0.0.0, 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.