Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and Unauthorized Data Access
Action: Patch Immediately
AI Analysis

Impact

A flaw in Oracle BI Publisher’s SOAP interface, classified as improper access control (CWE‑284) allows an unauthenticated attacker with network access to trigger a full application crash and repeatedly cause hangs, leading to complete denial of service. The same exploited path also grants the attacker the ability to read a subset of the data exposed by BI Publisher and to perform unauthorized insert, update or delete operations on that data, impacting confidentiality, integrity and availability.

Affected Systems

The vulnerability is present in Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0, all of which are part of Oracle Analytics. No other product or version information is provided.

Risk and Exploitability

The CVSS v3.1 base score is 8.6, reflecting high severity. The EPSS score is below 1 %, indicating a low to medium likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attack from the network is inferred as the vector via SOAP, as the description states that the flaw is exploitable over SOAP with unauthenticated network access.

Generated by OpenCVE AI on September 21, 2026 at 04:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle BI Publisher patch that resolves the SOAP-based denial of service and data manipulation issue for all affected versions.
  • If a patch is not immediately available, restrict or disable the SOAP endpoint on the BI Publisher server or limit network access to that interface to trusted hosts only.
  • Review and tighten database permissions for objects accessed through BI Publisher, ensuring only necessary users have modify rights and apply least‑privilege principles to reduce the impact of any residual unauthorized data access.

Generated by OpenCVE AI on September 21, 2026 at 04:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP-based DoS and Data Manipulation in Oracle BI Publisher

Mon, 21 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP-based Denial of Service and Data Access in Oracle BI Publisher
Weaknesses CWE-285

Mon, 21 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP-based Denial of Service and Data Access in Oracle BI Publisher
Weaknesses CWE-285

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP-based DoS and Data Modification in Oracle BI Publisher
Weaknesses CWE-200
CWE-284
CWE-400

Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP-based DoS and Data Modification in Oracle BI Publisher
Weaknesses CWE-200
CWE-284
CWE-400

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T00:03:17.073Z

Reserved: 2026-08-31T15:40:57.350Z

Link: CVE-2026-83284

cve-icon Vulnrichment

Updated: 2026-09-20T23:54:58.949Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:41.033

Modified: 2026-09-21T01:16:29.390

Link: CVE-2026-83284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses