Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Data and Availability Compromise
Action: Apply Patch
AI Analysis

Impact

A vulnerability in Oracle BI Publisher’s BI Platform Security component enables an attacker with low privileges and network access via HTTP to create, delete, or modify data, obtain unauthorized access to critical or all data, and induce a partial denial of service. The weakness permits the attacker to perform actions that impact confidentiality, integrity, and availability of the application.

Affected Systems

Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected. This refers to the Oracle Analytics product line integrated with BI Publisher.

Risk and Exploitability

The vulnerability carries a CVSS Base Score of 8.3 and an EPSS score of less than 1%, indicating that exploitation is unlikely but still possible. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) suggests remote exploitation over the network, low technical skill required, and a moderate impact on availability. It is not listed in CISA’s KEV catalog, and no official workaround or exploit is publicly known at this time. The likely attack path is a simple HTTP request exploiting insufficient access control checks, enabling unauthorized data manipulation and service degradation.

Generated by OpenCVE AI on September 20, 2026 at 08:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for BI Publisher that addresses the access control flaw for the affected versions
  • Restrict HTTP access to the BI Publisher interface to trusted networks, VPNs, or firewall rules to limit the exposed attack surface
  • Enforce strict role-based access controls within the application to ensure that only privileged users may perform creation, deletion, or modification of critical data

Generated by OpenCVE AI on September 20, 2026 at 08:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Access Control Flaw in Oracle BI Publisher Enables Data Manipulation and Partial Denial of Service

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Low Privilege Remote Access in Oracle BI Publisher
Weaknesses CWE-284

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Low Privilege Remote Access in Oracle BI Publisher
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:49.203Z

Reserved: 2026-08-31T15:40:57.352Z

Link: CVE-2026-83307

cve-icon Vulnrichment

Updated: 2026-09-18T18:16:08.262Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:43.640

Modified: 2026-09-18T19:16:54.563

Link: CVE-2026-83307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:45:17Z

Weaknesses