CVE-2026-83309
moderateAuthenticated Data-Access Flaw in Oracle BI Publisher Web Server (CVSS 8.5)
Oracle BI Publisher, part of Oracle Analytics, contains an easily exploitable vulnerability in its Web Server component that allows a low-privileged attacker with network access over HTTP to compromise the application. Successful attacks can impact products beyond Oracle BI Publisher (scope change) and can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data, as well as unauthorized update, insert, or delete access to some of that data. The flaw affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 and carries a CVSS 3.1 base score of 8.5 (high), driven by high confidentiality and low integrity impact. Exploitation requires valid low-privileged credentials, which lowers the immediate risk compared to unauthenticated flaws. The vulnerability is not listed in CISA's KEV catalog and no public proof-of-concept is known at this time.
What to do: Apply the Oracle Critical Patch Update that addresses this vulnerability and move to a fixed release of BI Publisher as soon as it is available for your version line (8.2.x, 12.2.1.4.x, or 26.01.x). Restrict network access to BI Publisher web server endpoints to trusted users and networks, and enforce least-privilege roles for all low-privileged accounts since exploitation requires valid credentials. Review BI Publisher and WebLogic access logs for anomalous data retrieval or unauthorized modifications by low-privilege users, keeping in mind that successful attacks may also affect additional products in scope.
| Oracle BI Publisher (Oracle Analytics) | 8.2.0.0.0 |
| Oracle BI Publisher (Oracle Analytics) | 12.2.1.4.0 |
| Oracle BI Publisher (Oracle Analytics) | 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.