CVE-2026-83305
moderateUnauthenticated Data Access Flaw in Oracle BI Publisher (BI Platform Security)
CVE-2026-83305 is an unauthenticated vulnerability in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics. An unauthenticated attacker with network access via HTTP can exploit it easily to compromise the BI Publisher instance, gaining unauthorized read access to critical data — potentially all data accessible to the product — plus unauthorized update, insert, and delete access to some data, and the ability to cause a partial denial of service. Affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The flaw carries a CVSS 3.1 base score of 8.6 (high), driven by high confidentiality impact. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the CVE is not on the CISA Known Exploited Vulnerabilities list.
What to do: Apply Oracle's Critical Patch Update that remediates this CVE on all affected Oracle BI Publisher deployments (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0) as soon as it is available. Restrict network access to BI Publisher HTTP endpoints so only trusted users and networks can reach the service, and place it behind an authenticated reverse proxy or VPN where possible. Review logs for unauthenticated HTTP requests to BI Platform Security endpoints and investigate any anomalous data exports, unauthorized modifications, or partial service outages.
| Oracle BI Publisher (Oracle Analytics, component: BI Platform Security) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.