CVE-2026-83284
moderateUnauthenticated SOAP Flaw in Oracle BI Publisher Allows DoS and Data Tampering
CVE-2026-83284 is an easily exploitable vulnerability in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics. An unauthenticated attacker with network access to the product's SOAP interface can trigger the flaw with no credentials and no user interaction. Successful exploitation allows the attacker to hang or repeatedly crash the BI Publisher service (complete denial of service), as well as gain unauthorized read access and unauthorized update, insert, or delete access to a subset of data reachable through BI Publisher. Versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are confirmed affected. No public proof-of-concept exists, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-83284 to every affected BI Publisher 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 deployment as soon as the patch is released. Until patched, restrict access to BI Publisher SOAP endpoints (block internet exposure, allow-list trusted sources) and review logs for unauthenticated SOAP requests, unexplained service hangs or crashes, and unauthorized data changes. If SOAP access is not required, disable the interface or place it behind an authenticated reverse proxy.
| Oracle BI Publisher (Oracle Analytics, component: BI Platform Security) | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.