ZeroHour

CVE-2026-83314

moderate

Authenticated SOAP Web Service Flaw in Oracle BI Publisher Enables Data Tampering and DoS

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

Oracle BI Publisher (part of Oracle Analytics) contains a vulnerability in its Web Service API that allows a low-privileged attacker with network access to send malicious SOAP requests and compromise the application. Successful exploitation gives the attacker unauthorized ability to create, delete, or modify critical data (or all data accessible to BI Publisher) and to cause a hang or frequently repeatable crash, resulting in complete denial of service. The flaw is rated high severity with a CVSS 3.1 base score of 8.1, with high impacts on integrity and availability but no impact on confidentiality. Affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, which span legacy, 12c-era, and current cloud-era release tracks. No public proof of concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE on your release track (8.2.x, 12.2.1.4.x, or 26.01.x). Restrict network access to the BI Publisher SOAP Web Service API to trusted sources and internal networks rather than exposing it to the internet. Review logs for anomalous SOAP API calls made by low-privilege service or user accounts, including unexpected document/report modifications or repeated application crashes and hangs.

Affected
Oracle BI Publisher (Oracle Analytics, Web Service API component)8.2.0.0.0
Oracle BI Publisher (Oracle Analytics, Web Service API component)12.2.1.4.0
Oracle BI Publisher (Oracle Analytics, Web Service API component)26.01.0.0.0
Estimated exposure
moderatelow thousands of internet-exposed BI Publisher endpoints, plus a larger unknown population of internal enterprise deployments (order of magnitude:… — Oracle BI Publisher is enterprise analytics middleware typically deployed inside corporate networks, and public internet scan services (Shodan/Censys) have historically shown only a few thousand internet-facing BI Publisher/OBIEE consoles,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.