CVE-2026-83310
moderateAuthenticated CSRF-Style Data Tampering in Oracle BI Publisher (BI Platform Security)
CVE-2026-83310 is a high-severity flaw in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics, affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. It is easily exploitable by a low-privileged attacker with network access via HTTP, but successful attacks require human interaction from a victim other than the attacker — consistent with a cross-site request forgery or similar browser-mediated vector that an admin or other user must be tricked into triggering. A successful exploit allows unauthorized creation, deletion, or modification of critical data, or of all BI Publisher-accessible data, plus unauthorized read access to that data, and because the scope changes, the impact can extend to additional products beyond BI Publisher itself. Organizations running the listed BI Publisher releases (often as part of Oracle Fusion Middleware or Oracle Analytics deployments) on HTTP-reachable networks are affected. There is no known public PoC, no CISA KEV listing, and no evidence of in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83310 to all affected BI Publisher installations (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0), prioritizing any instances reachable over HTTP. Verify that BI Publisher and its administrative/reporting consoles are not exposed to the public internet, and audit low-privileged accounts for suspicious data changes, since scope change means related products could be affected. Because exploitation requires victim interaction, remind BI Publisher users not to click untrusted links while authenticated to the platform.
| Oracle BI Publisher (Oracle Analytics, component: BI Platform Security) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.