CVE-2026-83313
moderateLow-Privilege Data Disclosure Flaw in Oracle BI Publisher (BI Platform Security)
CVE-2026-83313 is a vulnerability in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics, affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. It is easily exploitable by an attacker who already has a low-privileged account and network access via HTTP, allowing them to compromise Oracle BI Publisher. Successful exploitation results in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data, and because of a scope change the impact may extend significantly beyond BI Publisher itself to additional products. The flaw is confidentiality-only (CVSS 3.1: 7.7, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), requiring no user interaction. There is no evidence of in-the-wild exploitation and no public proof of concept, but Oracle addressed it via its Critical Patch Update process.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83313 to all BI Publisher deployments on 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Restrict network exposure of BI Publisher HTTP endpoints (e.g., /xmlpserver) to trusted users and VPN ranges, and audit low-privileged accounts for abnormal report or data access. Because the vulnerability has a scope change, also review access logs on adjacent Oracle Analytics products that share BI Platform Security.
| Oracle BI Publisher (Oracle Analytics, component: BI Platform Security) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.