ZeroHour

CVE-2026-83269

moderate

Unauthenticated Remote Takeover in Oracle BI Publisher (BI Platform Security)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Oracle BI Publisher, part of Oracle Analytics, contains an easily exploitable flaw in its BI Platform Security component that lets an unauthenticated attacker with HTTP network access compromise the application. Successful attacks result in a complete takeover of Oracle BI Publisher, with high impacts to confidentiality, integrity, and availability, reflected in a CVSS 3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N). Affected deployments include versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, spanning legacy on-premises OBIEE-era releases through the current analytics release. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, but the unauthenticated, network-reachable nature makes internet-facing consoles a high-priority patch target.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83269 to every BI Publisher instance running 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Until patched, remove BI Publisher HTTP endpoints from internet exposure and restrict access via VPN or an authenticating reverse proxy. Review web server and BI Publisher logs for unauthenticated HTTP requests as indicators of probing or exploitation attempts.

Affected
Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)
Estimated exposure
moderate≈ several thousand internet-exposed BI Publisher/OBIEE consoles, plus an unknown number of internal enterprise deployments — Estimated from typical internet-wide scan counts of reachable Oracle BI Publisher/OBIEE endpoints and the product's predominantly internal, enterprise-server deployment pattern; exact counts are unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.