ZeroHour

CVE-2026-83318

moderate

Low-Privilege Takeover Flaw in Oracle BI Publisher Administration Component

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83318 is a difficult-to-exploit vulnerability in the Administration component of Oracle BI Publisher (part of Oracle Analytics) that allows a low-privileged authenticated attacker with network access via HTTP to fully compromise the product. Exploitation requires valid low-level credentials and sending crafted HTTP requests to the affected server, but a successful attack results in a complete takeover of Oracle BI Publisher with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). Three supported versions are affected: 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Any organization exposing an affected BI Publisher instance to untrusted networks or hosting low-privilege user accounts is at risk. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses this CVE as soon as it is available for your release, since the affected list spans versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. In the meantime, restrict HTTP access to the BI Publisher administration interfaces to trusted VPN/admin networks, audit and prune low-privilege accounts, and review authentication logs for anomalous activity from ordinary users against administrative endpoints.

Affected
Oracle BI Publisher (Oracle Analytics, component: Administration)
Estimated exposure
moderateestimated on the order of a few thousand internet-exposed instances (1k–10k), plus a larger internal enterprise install base — Oracle BI Publisher is enterprise analytics middleware typically deployed inside corporate networks; public internet scans commonly show only low-thousands of exposed BI Publisher/administration consoles, while most instances are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.