CVE-2026-83267
moderateAuthenticated Privilege Escalation in Oracle BI Publisher Exposes Critical Data
Oracle BI Publisher, part of Oracle Analytics, contains an easily exploitable flaw in its BI Publisher Security component affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. A remote attacker with only low-privileged (authenticated) access via HTTP can leverage the flaw to compromise Oracle BI Publisher, and because the vulnerability changes scope, successful attacks may also significantly impact additional products beyond BI Publisher. Successful exploitation yields unauthorized access to critical data or complete read access to all BI Publisher-accessible data, along with unauthorized update, insert, or delete access to some of that data. The issue carries a CVSS 3.1 base score of 8.5 (high), driven by high confidentiality and low integrity impacts. There is no evidence of in-the-wild exploitation, the CVE is not in CISA's KEV catalog, and no public proof-of-concept is known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83267 to all BI Publisher deployments running 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0, prioritizing any instance reachable from the internet or shared networks. Restrict HTTP access to BI Publisher to trusted networks and enforce least-privilege roles for all authenticated users, since the flaw requires only a low-privileged account. Review audit logs for anomalous data reads or unauthorized inserts/updates/deletes by low-privilege accounts, and check whether other products in the deployment were accessed in ways consistent with the scope change.
| Oracle BI Publisher (Oracle Analytics) | 8.2.0.0.0 |
| Oracle BI Publisher (Oracle Analytics) | 12.2.1.4.0 |
| Oracle BI Publisher (Oracle Analytics) | 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.