Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote System Takeover
Action: Immediate Patch
AI Analysis

Impact

Oracle BI Publisher is vulnerable to an easily exploitable flaw that allows an attacker who already possesses high‑privilege credentials and can reach the HTTP endpoint to compromise the system. The vulnerability can jeopardise confidentiality, integrity and availability, enabling an attacker to effectively takeover the application. The impact may extend beyond the core product and affect other components that rely on the same underlying platform.

Affected Systems

Affected releases are Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. All installations of these versions should be treated as vulnerable until updated.

Risk and Exploitability

The CVSS 3.1 base score of 9.1 classifies this as critical, and the EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. This vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is network‑based, accessed through HTTP, and requires an attacker to have high‑privilege credentials. Successful exploitation can lead to full takeover of the BI Publisher instance and potentially ancillary products on the same infrastructure.

Generated by OpenCVE AI on September 20, 2026 at 08:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the official Oracle patch that addresses the BI Platform Security issue as described in the Oracle security advisory.
  • Restrict HTTP access to the BI Publisher service to trusted internal networks or IP ranges, and block exposure to the public internet.
  • Implement strict role‑based access control so that high‑privileged actions cannot be performed over HTTP without proper authentication and approval.
  • Continuously monitor HTTP request logs for anomalous patterns that might indicate exploitation attempts and review authentication and authorization controls regularly.

Generated by OpenCVE AI on September 20, 2026 at 08:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Authorization Bypass Allowing System Takeover in Oracle BI Publisher
Weaknesses CWE-284
CWE-94

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Remote Authorization Bypass Allowing System Takeover in Oracle BI Publisher
Weaknesses CWE-284
CWE-94

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:39.155Z

Reserved: 2026-08-31T15:40:57.350Z

Link: CVE-2026-83268

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:52.246Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:39.180

Modified: 2026-09-17T14:17:38.660

Link: CVE-2026-83268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:30:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management