ZeroHour

CVE-2026-83311

moderate

Low-Privilege SOAP Access Flaw in Oracle BI Publisher Exposes Critical Data (CVSS 8.5)

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

Oracle BI Publisher (Oracle Analytics), specifically the BI Platform Security component, contains an easily exploitable access control flaw in versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. A low-privileged authenticated attacker with network access can send crafted SOAP requests to compromise Oracle BI Publisher, and because the vulnerability changes scope, successful attacks may also significantly impact additional products beyond BI Publisher itself. Successful exploitation yields unauthorized read access to critical data or complete access to all Oracle BI Publisher accessible data, plus unauthorized update, insert, or delete access to some of that data (CVSS 3.1 base score 8.5, high). Organizations running any of the three affected versions on network-reachable infrastructure are exposed; the flaw requires only a low-privilege account and no user interaction. The issue is not on the CISA KEV list, no public proof of concept is known, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates this issue to all BI Publisher deployments running 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Until patched, restrict network access to SOAP endpoints (VPN/IP allowlisting), audit and minimize low-privilege accounts, and review logs for anomalous SOAP requests or unexpected data reads and modifications by low-privilege users. Because the scope change means other integrated products may also be impacted, verify trust and data flows between BI Publisher and connected systems after patching.

Affected
Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Estimated exposure
moderate≈1,000–10,000 internet-exposed BI Publisher instances, plus a larger unknown number of internal-only enterprise deployments — Oracle BI Publisher is enterprise middleware typically deployed behind firewalls, and public internet-wide scan results for exposed Oracle BI/middleware SOAP and console endpoints generally fall in the low thousands; total internal…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.