ZeroHour

CVE-2026-83305

moderate

Unauthenticated Data Access Flaw in Oracle BI Publisher (BI Platform Security)

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83305 is an unauthenticated vulnerability in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics. An unauthenticated attacker with network access via HTTP can exploit it easily to compromise the BI Publisher instance, gaining unauthorized read access to critical data — potentially all data accessible to the product — plus unauthorized update, insert, and delete access to some data, and the ability to cause a partial denial of service. Affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The flaw carries a CVSS 3.1 base score of 8.6 (high), driven by high confidentiality impact. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the CVE is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply Oracle's Critical Patch Update that remediates this CVE on all affected Oracle BI Publisher deployments (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0) as soon as it is available. Restrict network access to BI Publisher HTTP endpoints so only trusted users and networks can reach the service, and place it behind an authenticated reverse proxy or VPN where possible. Review logs for unauthenticated HTTP requests to BI Platform Security endpoints and investigate any anomalous data exports, unauthorized modifications, or partial service outages.

Affected
Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)
Estimated exposure
moderate≈ 1,000–10,000 internet-exposed BI Publisher instances (order of a few thousand), plus an unknown larger number of internal enterprise deployments — Oracle BI Publisher is enterprise reporting software typically deployed on-premises by mid-to-large organizations; public internet scans historically show only low-thousands of exposed BI Publisher/OBIEE login endpoints, with most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.