ZeroHour

CVE-2026-83284

moderate

Unauthenticated SOAP Flaw in Oracle BI Publisher Allows DoS and Data Tampering

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83284 is an easily exploitable vulnerability in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics. An unauthenticated attacker with network access to the product's SOAP interface can trigger the flaw with no credentials and no user interaction. Successful exploitation allows the attacker to hang or repeatedly crash the BI Publisher service (complete denial of service), as well as gain unauthorized read access and unauthorized update, insert, or delete access to a subset of data reachable through BI Publisher. Versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are confirmed affected. No public proof-of-concept exists, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-83284 to every affected BI Publisher 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 deployment as soon as the patch is released. Until patched, restrict access to BI Publisher SOAP endpoints (block internet exposure, allow-list trusted sources) and review logs for unauthenticated SOAP requests, unexplained service hangs or crashes, and unauthorized data changes. If SOAP access is not required, disable the interface or place it behind an authenticated reverse proxy.

Affected
Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Estimated exposure
moderate≈ low thousands of internet-exposed BI Publisher/SOAP endpoints, with a larger base of tens of thousands of on-premises enterprise installations overall — Oracle BI Publisher is an on-premises enterprise reporting server typically deployed inside corporate networks, and public internet scan data for Oracle BI/OBIEE-style consoles historically shows only a few thousand internet-reachable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

In the news

No ingested article mentions this CVE yet.