CVE-2026-83268
moderateHigh-Privilege Takeover Flaw in Oracle BI Publisher (BI Platform Security)
CVE-2026-83268 is a critical (CVSS 9.1) vulnerability in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics, affecting versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. It is easily exploitable by an already high-privileged, authenticated attacker who has network access to the BI Publisher HTTP interface, so the practical risk is privilege escalation and full product takeover from an administrative foothold rather than an anonymous internet attack. Successful exploitation results in complete compromise of confidentiality, integrity and availability of Oracle BI Publisher, and because the vulnerability has a scope change (S:C), attacks may also significantly impact additional products beyond BI Publisher itself. Organizations running any of the three listed versions, whether on-premises or in Oracle Cloud, are affected. No public proof-of-concept exists and the flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83268 to all BI Publisher installations on versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Restrict HTTP access to BI Publisher endpoints (especially administrative consoles) to trusted networks and VPNs, and enforce least-privilege on BI Publisher administrator accounts since the flaw requires high privileges to trigger. Review authentication and administrative-action logs for anomalous activity by high-privileged accounts, and monitor Oracle's advisory for scope-change impacts on adjacent Analytics products.
| Oracle BI Publisher (Oracle Analytics, component: BI Platform Security) | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.