ZeroHour

CVE-2026-83297

moderate

Low-Privilege LDAP Attack on Oracle BI Publisher Security Component Exposes All Data

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83297 is a flaw in the BI Platform Security component of Oracle BI Publisher (part of Oracle Analytics) affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. A low-privileged attacker with network access via LDAP can exploit it easily (no user interaction required) to compromise Oracle BI Publisher. Successful attacks give the attacker unauthorized ability to create, delete, or modify critical data — or all BI Publisher-accessible data — as well as unauthorized read access up to complete disclosure of that data; availability is not impacted (CVSS 3.1 base score 8.1, high confidentiality and integrity impact). The flaw is presumably addressed in an Oracle Critical Patch Update, and defenders running the listed versions, especially those with LDAP-integrated authentication, are affected. There is no evidence of in-the-wild exploitation: the CVE is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83297 to all Oracle BI Publisher deployments on versions 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Until patched, restrict network and LDAP access to BI Publisher to trusted sources, enforce least-privilege LDAP bind accounts, and review logs for suspicious data modifications or access by low-privilege accounts.

Affected
Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)
Estimated exposure
moderate≈ low thousands of internet-exposed BI Publisher endpoints, on the order of tens of thousands of enterprise installations overall (estimate) — Oracle BI Publisher is enterprise middleware typically deployed on-premises behind perimeters, and public internet scans (e.g., Shodan/Censys) historically show only a few thousand internet-facing Oracle BI Publisher/Fusion Middleware…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.