ZeroHour

CVE-2026-83313

moderate

Low-Privilege Data Disclosure Flaw in Oracle BI Publisher (BI Platform Security)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83313 is a vulnerability in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics, affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. It is easily exploitable by an attacker who already has a low-privileged account and network access via HTTP, allowing them to compromise Oracle BI Publisher. Successful exploitation results in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data, and because of a scope change the impact may extend significantly beyond BI Publisher itself to additional products. The flaw is confidentiality-only (CVSS 3.1: 7.7, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), requiring no user interaction. There is no evidence of in-the-wild exploitation and no public proof of concept, but Oracle addressed it via its Critical Patch Update process.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83313 to all BI Publisher deployments on 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. Restrict network exposure of BI Publisher HTTP endpoints (e.g., /xmlpserver) to trusted users and VPN ranges, and audit low-privileged accounts for abnormal report or data access. Because the vulnerability has a scope change, also review access logs on adjacent Oracle Analytics products that share BI Platform Security.

Affected
Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)
Estimated exposure
moderatelow thousands of internet-exposed BI Publisher instances (plus an unknown larger number on internal enterprise networks) — Oracle BI Publisher is enterprise analytics middleware that public internet scans have historically shown exposed in the low thousands via its xmlpserver web endpoint, with most deployments behind corporate networks, so a rough order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.