Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the Security component of Oracle BI Publisher, allowing an attacker to execute unauthorized read, write, or delete actions on data that should be protected. Successful exploitation results in a confidentiality breach by providing full access to all data accessible by the publisher and an integrity impact through the ability to update, insert, or delete data. The weakness is a lack of proper access control, as described by the CVE description and the CVSS vector.

Affected Systems

The affected products are Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Users running these specific builds and exposing them to HTTP traffic are within scope, with no other versions or components listed as vulnerable.

Risk and Exploitability

The CVSS base score of 8.5 indicates high severity, with a high confidentiality impact and a low integrity impact. The scope change allows the impact to extend beyond the initially compromised environment. The EPSS score is below 1%, indicating a very low but non-zero probability of exploitation in the wild. The likelihood of attack is via direct HTTP traffic from a low-privileged attacker with network access, exploiting weak access control to gain unauthorized read, write, or delete capabilities over Oracle BI Publisher data.

Generated by OpenCVE AI on September 21, 2026 at 22:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an Oracle patch or upgrade to a non‑affected version of Oracle BI Publisher
  • If a patch is unavailable, isolate the affected BI Publisher installation from untrusted networks or restrict HTTP access to authorized hosts and monitor for failed authentication attempts and unauthorized data modification requests
  • If users require remote access, enforce strong authentication and consider network segmentation to limit exposure

Generated by OpenCVE AI on September 21, 2026 at 22:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle BI Publisher via HTTP

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle BI Publisher via HTTP

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Network-Exploitable Oracle BI Publisher Vulnerability Allows Unauthorized Data Access
Weaknesses CWE-200
CWE-284

Thu, 17 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Network-Exploitable Oracle BI Publisher Vulnerability Allows Unauthorized Data Access
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:06:28.071Z

Reserved: 2026-08-31T15:40:57.350Z

Link: CVE-2026-83267

cve-icon Vulnrichment

Updated: 2026-09-21T19:06:24.457Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:39.063

Modified: 2026-09-21T20:17:33.397

Link: CVE-2026-83267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T22:15:17Z

Weaknesses