Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-08-18
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle BI Publisher’s platform security module contains a defect that lets an attacker with low privileges and network connectivity over HTTP create, delete or modify data, and potentially cause a partial denial of service. The flaw exposes confidentiality, integrity, and availability, allowing unauthorized access to critical data or all data published through BI Publisher.

Affected Systems

The vulnerability affects Oracle BI Publisher, a component of Oracle Analytics. Versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 are known to be vulnerable and have been documented by Oracle’s security advisory.

Risk and Exploitability

The issue carries a CVSS 3.1 score of 8.3, indicating high severity. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, implying no publicly known exploits at the time of reporting. The likely attack vector is over the network via HTTP, requiring only low privileges to exploit, making this a readily exploitable threat for attackers with network access to the application.

Generated by OpenCVE AI on August 21, 2026 at 12:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or upgrade-oracle BI Publisher to a version that excludes the vulnerable platform security component. This is the recommended official resolution.
  • Limit HTTP traffic to Oracle BI Publisher to approved IP ranges or use a VPN to restrict access. Ensure that only trusted network segments can reach the application to reduce the attack surface.
  • Enable detailed audit logging for data creation, deletion, and modification operations, and monitor logs for anomalous activity. This adds detection capability while remediation is pending.

Generated by OpenCVE AI on August 21, 2026 at 12:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Abuse of Oracle BI Publisher Platform Security

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T03:55:53.713Z

Reserved: 2026-07-08T15:52:20.746Z

Link: CVE-2026-61305

cve-icon Vulnrichment

Updated: 2026-08-19T12:12:43.763Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:59.123

Modified: 2026-08-24T15:51:10.427

Link: CVE-2026-61305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:15:14Z

Weaknesses