ZeroHour

CVE-2026-83303

moderate

Privilege Escalation via SOAP in Oracle BI Publisher (BI Platform Security)

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83303 is an authorization flaw in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics, affecting versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. A remote attacker holding only low-privileged credentials can trigger the flaw over the network through the SOAP interface, and it is rated as easily exploitable. Successful attacks allow the attacker to compromise Oracle BI Publisher entirely, gaining unauthorized creation, deletion or modification access to critical data or all BI Publisher-accessible data, along with unauthorized read access to a subset of that data. Because the vulnerability carries a scope change, successful attacks may also significantly impact additional products beyond BI Publisher itself. The issue is rated CVSS 3.1 8.5 (high); it is not on the CISA KEV list, no public PoC is known, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83303 to all affected BI Publisher installations (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0). Until patched, restrict network access to the BI Publisher SOAP interface and audit low-privileged accounts for anomalous SOAP requests or unexpected data changes. Because of the scope change, also verify the integrity of data in integrated systems reachable from BI Publisher.

Affected
Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Estimated exposure
moderate≈ a few thousand internet-exposed BI Publisher endpoints, plus a larger internal enterprise install base (low tens of thousands of instances overall) — Oracle BI Publisher is an enterprise on-premises analytics product; public internet scan services typically enumerate only a few thousand exposed Oracle BI Publisher/OBIEE-style endpoints, with most deployments sitting inside corporate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.