Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker with low privileges and network access via LDAP to create, delete, or modify critical data within Oracle BI Publisher. As a result the attacker can also gain unauthorized access to all data that the publisher can reach, causing significant confidentiality and integrity damage.

Affected Systems

Affected versions are Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. The product is part of Oracle Analytics and is used to publish reports and data. No other versions are mentioned as affected.

Risk and Exploitability

The CVSS base score of 8.1 indicates high severity. The reported EPSS is less than 1%, suggesting exploitation is not widespread but still possible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a low‑privileged network user that can reach the LDAP service; the description states such an attacker can exploit the flaw. Exploitation would require network connectivity to the LDAP interface of BI Publisher and no special privileges beyond the low‑privilege account.

Generated by OpenCVE AI on September 18, 2026 at 18:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0.
  • Restrict LDAP authentication to trusted users and isolate the BI Publisher LDAP service from external networks using firewall rules.
  • Monitor BI Publisher audit logs for suspicious data modification or access attempts and respond promptly.

Generated by OpenCVE AI on September 18, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via LDAP in Oracle BI Publisher

Wed, 16 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via LDAP in Oracle BI Publisher
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:49.489Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83297

cve-icon Vulnrichment

Updated: 2026-09-18T18:16:15.500Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:42.533

Modified: 2026-09-18T19:16:53.540

Link: CVE-2026-83297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:30:12Z

Weaknesses