CVE-2026-83312
moderateLow-privilege data disclosure in Oracle BI Publisher (E-Business Suite XDO)
CVE-2026-83312 is a confidentiality-focused flaw in the E-Business Suite XDO component of Oracle BI Publisher, part of Oracle Analytics, affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. An authenticated attacker holding only low privileges, with network access to the BI Publisher service over HTTP, can exploit the flaw without any user interaction. Successful attacks result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data, and because the vulnerability carries a scope change (S:C), the impact can extend significantly to additional products beyond BI Publisher itself. The flaw is easily exploitable per Oracle's advisory and scores 7.7 (High) on CVSS 3.1 with high confidentiality impact only. No public proof of concept exists, the flaw is not on CISA's KEV list, and no exploitation has been observed in the wild.
What to do: Apply Oracle's Critical Patch Update for this cycle to all BI Publisher installations running 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0 as soon as patches are released. Restrict HTTP access to BI Publisher/XDO endpoints to trusted networks or VPN, enforce least privilege on BI Publisher accounts, and audit logs for anomalous data or report retrieval by low-privilege users.
| Oracle BI Publisher (Oracle Analytics, component: E-Business Suite - XDO) | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: E-Business Suite - XDO). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.