ZeroHour

CVE-2026-83309

moderate

Authenticated Data-Access Flaw in Oracle BI Publisher Web Server (CVSS 8.5)

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

Oracle BI Publisher, part of Oracle Analytics, contains an easily exploitable vulnerability in its Web Server component that allows a low-privileged attacker with network access over HTTP to compromise the application. Successful attacks can impact products beyond Oracle BI Publisher (scope change) and can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data, as well as unauthorized update, insert, or delete access to some of that data. The flaw affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 and carries a CVSS 3.1 base score of 8.5 (high), driven by high confidentiality and low integrity impact. Exploitation requires valid low-privileged credentials, which lowers the immediate risk compared to unauthenticated flaws. The vulnerability is not listed in CISA's KEV catalog and no public proof-of-concept is known at this time.

What to do: Apply the Oracle Critical Patch Update that addresses this vulnerability and move to a fixed release of BI Publisher as soon as it is available for your version line (8.2.x, 12.2.1.4.x, or 26.01.x). Restrict network access to BI Publisher web server endpoints to trusted users and networks, and enforce least-privilege roles for all low-privileged accounts since exploitation requires valid credentials. Review BI Publisher and WebLogic access logs for anomalous data retrieval or unauthorized modifications by low-privilege users, keeping in mind that successful attacks may also affect additional products in scope.

Affected
Oracle BI Publisher (Oracle Analytics)8.2.0.0.0
Oracle BI Publisher (Oracle Analytics)12.2.1.4.0
Oracle BI Publisher (Oracle Analytics)26.01.0.0.0
Estimated exposure
moderate≈1,000–10,000 internet-exposed BI Publisher instances, plus an unknown larger number of internal enterprise deployments (estimate) — Oracle BI Publisher is enterprise middleware typically deployed on internal networks; public internet-wide scans have historically shown only low thousands of exposed BI Publisher web endpoints, so this is an order-of-magnitude estimate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.