ZeroHour

CVE-2026-83308

moderate

Authenticated SOAP Flaw in Oracle BI Publisher Enables Data Tampering and DoS

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

An easily exploitable vulnerability in the BI Platform Security component of Oracle BI Publisher allows a low-privileged, authenticated attacker with network access to compromise the application through its SOAP interface. Successful attacks can result in unauthorized creation, deletion, or modification of critical data or all data accessible to BI Publisher, as well as the ability to cause a hang or frequently repeatable crash (complete denial of service). Organizations running BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0 as part of Oracle Analytics deployments are affected. The flaw carries a CVSS 3.1 base score of 8.1 (high), reflecting a network attack vector with low privileges required and high impact on both integrity and availability. No public proof of concept is known and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is currently no evidence of in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83308 to every installation of BI Publisher 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Until patched, restrict network access to BI Publisher SOAP endpoints to trusted sources and enforce least-privilege credentials for service and reporting accounts. Review audit logs for unauthorized data changes or repeated crashes and hangs attributable to low-privileged accounts.

Affected
Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Estimated exposure
moderateLikely a few thousand to low tens of thousands of internet-exposed BI Publisher consoles, plus many more internal enterprise deployments — BI Publisher is enterprise on-premises and cloud analytics middleware; public scan engines typically show only a few thousand to low tens of thousands of internet-reachable BI Publisher/Oracle Analytics login and SOAP endpoints, since most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.