CVE-2026-83311
moderateLow-Privilege SOAP Access Flaw in Oracle BI Publisher Exposes Critical Data (CVSS 8.5)
Oracle BI Publisher (Oracle Analytics), specifically the BI Platform Security component, contains an easily exploitable access control flaw in versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. A low-privileged authenticated attacker with network access can send crafted SOAP requests to compromise Oracle BI Publisher, and because the vulnerability changes scope, successful attacks may also significantly impact additional products beyond BI Publisher itself. Successful exploitation yields unauthorized read access to critical data or complete access to all Oracle BI Publisher accessible data, plus unauthorized update, insert, or delete access to some of that data (CVSS 3.1 base score 8.5, high). Organizations running any of the three affected versions on network-reachable infrastructure are exposed; the flaw requires only a low-privilege account and no user interaction. The issue is not on the CISA KEV list, no public proof of concept is known, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates this issue to all BI Publisher deployments running 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Until patched, restrict network access to SOAP endpoints (VPN/IP allowlisting), audit and minimize low-privilege accounts, and review logs for anomalous SOAP requests or unexpected data reads and modifications by low-privilege users. Because the scope change means other integrated products may also be impacted, verify trust and data flows between BI Publisher and connected systems after patching.
| Oracle BI Publisher (Oracle Analytics, component: BI Platform Security) | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.