CVE-2026-83308
moderateAuthenticated SOAP Flaw in Oracle BI Publisher Enables Data Tampering and DoS
An easily exploitable vulnerability in the BI Platform Security component of Oracle BI Publisher allows a low-privileged, authenticated attacker with network access to compromise the application through its SOAP interface. Successful attacks can result in unauthorized creation, deletion, or modification of critical data or all data accessible to BI Publisher, as well as the ability to cause a hang or frequently repeatable crash (complete denial of service). Organizations running BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0 as part of Oracle Analytics deployments are affected. The flaw carries a CVSS 3.1 base score of 8.1 (high), reflecting a network attack vector with low privileges required and high impact on both integrity and availability. No public proof of concept is known and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is currently no evidence of in-the-wild exploitation.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83308 to every installation of BI Publisher 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Until patched, restrict network access to BI Publisher SOAP endpoints to trusted sources and enforce least-privilege credentials for service and reporting accounts. Review audit logs for unauthorized data changes or repeated crashes and hangs attributable to low-privileged accounts.
| Oracle BI Publisher (Oracle Analytics, component: BI Platform Security) | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.