ZeroHour

CVE-2026-83315

moderate

Authenticated SOAP Privilege Escalation Enables Full Takeover of Oracle BI Publisher

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83315 is a high-severity (CVSS 8.8) flaw in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics. A remote attacker with only low-privileged credentials and network access to the product's SOAP interface can exploit the weakness, which requires no user interaction and is rated easy to exploit. A successful attack results in a complete takeover of Oracle BI Publisher, with high impact on the confidentiality, integrity, and availability of the reporting platform and the data it exposes. Affected deployments are on-premises and cloud installations running versions 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0. No public proof of concept is known and the issue is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is currently considered theoretical.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83315 to all BI Publisher 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 installations as soon as it is available, prioritizing any instance whose SOAP endpoints are reachable from less-trusted networks. Restrict or place an allow-list in front of SOAP/web-service access so only trusted integration clients can reach it, and audit low-privileged accounts for suspicious activity. Review BI Publisher logs for unexpected SOAP requests or privilege changes by ordinary accounts, and rotate credentials for any low-privilege service or user accounts that had access to the interface.

Affected
Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Estimated exposure
moderate≈ a few thousand internet-exposed BI Publisher instances, plus an unknown larger population of intranet-only enterprise deployments — Oracle BI Publisher is enterprise on-premises reporting middleware rather than mass-market software, and public internet scans typically surface only low thousands of reachable BI Publisher/SOAP endpoints, while most instances sit on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.