CVE-2026-83302
moderateAuthenticated Data Exposure in Oracle BI Publisher 12.2.1.4.0
Oracle BI Publisher 12.2.1.4.0 (part of Oracle Analytics, BI Publisher Security component) contains an easily exploitable flaw reachable over HTTP by an attacker holding only low-privileged credentials. Successful exploitation yields unauthorized access to critical data — or complete access to all data reachable through Oracle BI Publisher — plus the ability to cause a partial denial of service. Because the vulnerability carries a scope change (CVSS 3.1 8.5, AV:N/AC:L/PR:L/S:C/C:H/A:L), successful attacks may also significantly impact products beyond BI Publisher itself. Any organization running the affected 12.2.1.4.0 release, particularly instances reachable on a network by low-privilege or internal users, is affected. No public proof of concept is known and the flaw is not on the CISA KEV catalog, so exploitation status is none known as of this writing.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw to all BI Publisher 12.2.1.4.0 instances and any bundled deployments (e.g., OBIEE/Fusion Middleware) as soon as the patch is available. Restrict HTTP access to BI Publisher so only trusted networks, VPN, or SSO-fronted users can reach it, and audit low-privilege accounts for anomalous report/data access or unexpected service disruption.
| Oracle BI Publisher (Oracle Analytics, component: BI Publisher Security) | 12.2.1.4.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.