ZeroHour

CVE-2026-83267

moderate

Authenticated Privilege Escalation in Oracle BI Publisher Exposes Critical Data

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

Oracle BI Publisher, part of Oracle Analytics, contains an easily exploitable flaw in its BI Publisher Security component affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. A remote attacker with only low-privileged (authenticated) access via HTTP can leverage the flaw to compromise Oracle BI Publisher, and because the vulnerability changes scope, successful attacks may also significantly impact additional products beyond BI Publisher. Successful exploitation yields unauthorized access to critical data or complete read access to all BI Publisher-accessible data, along with unauthorized update, insert, or delete access to some of that data. The issue carries a CVSS 3.1 base score of 8.5 (high), driven by high confidentiality and low integrity impacts. There is no evidence of in-the-wild exploitation, the CVE is not in CISA's KEV catalog, and no public proof-of-concept is known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83267 to all BI Publisher deployments running 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0, prioritizing any instance reachable from the internet or shared networks. Restrict HTTP access to BI Publisher to trusted networks and enforce least-privilege roles for all authenticated users, since the flaw requires only a low-privileged account. Review audit logs for anomalous data reads or unauthorized inserts/updates/deletes by low-privilege accounts, and check whether other products in the deployment were accessed in ways consistent with the scope change.

Affected
Oracle BI Publisher (Oracle Analytics)8.2.0.0.0
Oracle BI Publisher (Oracle Analytics)12.2.1.4.0
Oracle BI Publisher (Oracle Analytics)26.01.0.0.0
Estimated exposure
moderate≈ low thousands of internet-exposed BI Publisher instances, plus a larger internal enterprise install base — BI Publisher is on-premises enterprise middleware typically deployed inside corporate networks; public internet scans historically show only a few thousand exposed Oracle BI/BI Publisher endpoints, while many more instances run on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.