Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability resides in the Oracle BI Publisher component of Oracle Analytics. It allows an unauthenticated attacker who can reach the application via HTTP to compromise the system. The attack grants full control, resulting in loss of confidentiality, integrity, and availability. The flaw is classified as authentication bypass (CWE‑287) and improper privilege management (CWE‑306). The likely attack vector is network, specifically HTTP traffic to the BI Publisher service.

Affected Systems

Affected products are Oracle BI Publisher from Oracle Corporation. The specific affected releases are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Other versions are not listed as impacted.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity and the attack surface is remote, unauthenticated, with low attack complexity, no user interaction, and the vulnerability is unscoped. The EPSS score is below 1%, suggesting that mass exploitation is currently low, and it is not listed in the CISA KEV catalog. Nonetheless, the combination of high severity and network reachability means patching should be treated as a high priority, as attackers could still exploit the flaw in targeted campaigns.

Generated by OpenCVE AI on September 18, 2026 at 18:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle BI Publisher patch or upgrade to a fixed version as announced in the Oracle security advisory.
  • Limit HTTP access to the BI Publisher application to trusted internal networks or specific IP ranges, blocking exposure to the public internet.
  • Disable anonymous web access and enforce mandatory authentication for all BI Publisher users.

Generated by OpenCVE AI on September 18, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Remote Takeover of Oracle BI Publisher

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T03:56:05.302Z

Reserved: 2026-08-31T15:40:57.350Z

Link: CVE-2026-83269

cve-icon Vulnrichment

Updated: 2026-09-15T22:44:57.765Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:39.290

Modified: 2026-09-22T04:17:59.430

Link: CVE-2026-83269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:00:06Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function