ZeroHour

CVE-2026-83312

moderate

Low-privilege data disclosure in Oracle BI Publisher (E-Business Suite XDO)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83312 is a confidentiality-focused flaw in the E-Business Suite XDO component of Oracle BI Publisher, part of Oracle Analytics, affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. An authenticated attacker holding only low privileges, with network access to the BI Publisher service over HTTP, can exploit the flaw without any user interaction. Successful attacks result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data, and because the vulnerability carries a scope change (S:C), the impact can extend significantly to additional products beyond BI Publisher itself. The flaw is easily exploitable per Oracle's advisory and scores 7.7 (High) on CVSS 3.1 with high confidentiality impact only. No public proof of concept exists, the flaw is not on CISA's KEV list, and no exploitation has been observed in the wild.

What to do: Apply Oracle's Critical Patch Update for this cycle to all BI Publisher installations running 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0 as soon as patches are released. Restrict HTTP access to BI Publisher/XDO endpoints to trusted networks or VPN, enforce least privilege on BI Publisher accounts, and audit logs for anomalous data or report retrieval by low-privilege users.

Affected
Oracle BI Publisher (Oracle Analytics, component: E-Business Suite - XDO)8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Estimated exposure
moderatelikely a few thousand internet-exposed instances (order of 1k-10k), concentrated in enterprise Oracle E-Business Suite deployments — Oracle BI Publisher is enterprise software typically deployed alongside E-Business Suite in mid-to-large organizations, and public internet scans have historically shown only a few thousand exposed Oracle BI Publisher/EBS web endpoints…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: E-Business Suite - XDO). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.