
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-83324 is an authorization bypass vulnerability in the BI Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), part of the Oracle Analytics product family. It affects versions 8.2.0.0.0 and 26.01.0.0.0. The vulnerability was disclosed and patched on September 15, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 7.1 (High) (Oracle Advisory).
The vulnerability is classified as an authorization bypass (CWE not explicitly specified, but consistent with improper access control) within the BI Platform Security component of Oracle Business Intelligence Enterprise Edition. A low-privileged attacker with network access via HTTP can exploit this flaw to perform unauthorized create, delete, or modify operations on critical data, as well as read a subset of data beyond their authorized permissions. The attack complexity is rated High, meaning exploitation requires specific conditions or configuration states to be met. The scope is marked as Changed, indicating that a successful exploit can impact resources beyond the vulnerable component itself, potentially affecting additional connected Oracle products (Oracle Advisory).
Successful exploitation allows a low-privileged attacker to perform unauthorized creation, deletion, or modification of critical data accessible through Oracle Business Intelligence Enterprise Edition, as well as read a subset of that data without authorization. The Changed scope designation means the impact can extend beyond OBIEE itself to additional connected products or systems. Availability is not impacted, but the confidentiality and integrity risks are significant, particularly in environments where OBIEE is integrated with sensitive enterprise data sources (Oracle Advisory).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.0026 (0.26%), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The High attack complexity requirement further limits opportunistic exploitation (Oracle Advisory).
Oracle released a security patch for CVE-2026-83324 on September 15, 2026, as part of the September 2026 Critical Security Patch Update. Affected organizations should apply the patch immediately for Oracle Business Intelligence Enterprise Edition versions 8.2.0.0.0 and 26.01.0.0.0. As interim measures, Oracle recommends restricting network access to OBIEE to authorized users only, enforcing the principle of least privilege for all user accounts, and monitoring low-privileged user activity for unusual data access or modification patterns. Network segmentation can help limit the blast radius if exploitation occurs prior to patching (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."