ZeroHour

CVE-2026-83320

moderate

Interaction-Dependent Admin Flaw in Oracle BI Publisher Exposes All Report Data

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83320 is a high-severity (CVSS 7.6) vulnerability in the Administration component of Oracle BI Publisher, part of Oracle Analytics, affecting versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. A low-privileged attacker with network access via HTTP can trigger the flaw, but a successful attack requires a human victim (other than the attacker) to interact — a pattern consistent with a CSRF-style attack against the administrative interface. If exploited, the attacker can gain unauthorized read access to critical data or all data accessible to BI Publisher, as well as unauthorized update, insert or delete access to some of that data; because the scope changes, attacks may also significantly impact products beyond BI Publisher itself. Organizations running on-premises BI Publisher (standalone or as part of Oracle Analytics Server / Fusion Middleware) are the primary affected population, especially any instance with the admin console reachable by low-privilege or internal users. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so exploitation is not currently known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83320 to all BI Publisher 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 installations. In the interim, restrict network access to BI Publisher administration pages (including /xmlpserver) to trusted administrative networks, enforce strict SameSite cookie behavior where supported, and review logs for anomalous data access by low-privilege accounts. Verify no internet-facing exposure of the admin console using external scanning.

Affected
Oracle BI Publisher (Oracle Analytics)8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Estimated exposure
moderate≈ low thousands of internet-exposed BI Publisher instances, plus a larger unquantified set of internal enterprise deployments — BI Publisher (typically via the /xmlpserver endpoint on WebLogic) shows up in public internet scans in the low-thousands range, while the majority of deployments are internal enterprise BI stacks not reachable from the internet.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.