CVE-2026-83318
moderateLow-Privilege Takeover Flaw in Oracle BI Publisher Administration Component
CVE-2026-83318 is a difficult-to-exploit vulnerability in the Administration component of Oracle BI Publisher (part of Oracle Analytics) that allows a low-privileged authenticated attacker with network access via HTTP to fully compromise the product. Exploitation requires valid low-level credentials and sending crafted HTTP requests to the affected server, but a successful attack results in a complete takeover of Oracle BI Publisher with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). Three supported versions are affected: 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Any organization exposing an affected BI Publisher instance to untrusted networks or hosting low-privilege user accounts is at risk. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses this CVE as soon as it is available for your release, since the affected list spans versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. In the meantime, restrict HTTP access to the BI Publisher administration interfaces to trusted VPN/admin networks, audit and prune low-privilege accounts, and review authentication logs for anomalous activity from ordinary users against administrative endpoints.
| Oracle BI Publisher (Oracle Analytics, component: Administration) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.