CVE-2026-83314
moderateAuthenticated SOAP Web Service Flaw in Oracle BI Publisher Enables Data Tampering and DoS
Oracle BI Publisher (part of Oracle Analytics) contains a vulnerability in its Web Service API that allows a low-privileged attacker with network access to send malicious SOAP requests and compromise the application. Successful exploitation gives the attacker unauthorized ability to create, delete, or modify critical data (or all data accessible to BI Publisher) and to cause a hang or frequently repeatable crash, resulting in complete denial of service. The flaw is rated high severity with a CVSS 3.1 base score of 8.1, with high impacts on integrity and availability but no impact on confidentiality. Affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, which span legacy, 12c-era, and current cloud-era release tracks. No public proof of concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE on your release track (8.2.x, 12.2.1.4.x, or 26.01.x). Restrict network access to the BI Publisher SOAP Web Service API to trusted sources and internal networks rather than exposing it to the internet. Review logs for anomalous SOAP API calls made by low-privilege service or user accounts, including unexpected document/report modifications or repeated application crashes and hangs.
| Oracle BI Publisher (Oracle Analytics, Web Service API component) | 8.2.0.0.0 |
| Oracle BI Publisher (Oracle Analytics, Web Service API component) | 12.2.1.4.0 |
| Oracle BI Publisher (Oracle Analytics, Web Service API component) | 26.01.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.