Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification and Availability Impact
Action: Immediate Patch
AI Analysis

Impact

Oracle BI Publisher’s SOAP interface exposes a flaw that allows a low‑privileged attacker with network access to create, delete or modify critical data and to trigger complete application hangs or crashes. The vulnerability is identified in the BI Platform Security component and occurs when SOAP requests bypass sufficient access controls. The impact is direct loss of data integrity and application availability, potentially affecting all data exposed through Oracle BI Publisher.

Affected Systems

Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 are affected. Any deployment that has the SOAP API exposed to external networks is susceptible to these attacks.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 reflects severe integrity and availability consequences. The EPSS score of <1% indicates a very low probability of exploitation in the current threat environment, but the vulnerability is not listed in CISA’s KEV catalog, so the potential business impact remains significant. The likely attack vector is over the network via crafted SOAP requests; the description suggests that low‑privilege credentials or even no authentication are sufficient, although this is inferred rather than explicitly documented.

Generated by OpenCVE AI on September 20, 2026 at 08:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Oracle BI Publisher to the latest patched release to eliminate the known vulnerability.
  • Restrict network access to the SOAP API by configuring firewalls or VPNs so that only trusted hosts can reach the service.
  • Enforce strict authentication and authorization on the SOAP interface, ensuring that low‑privileged users cannot invoke data‑modifying operations.

Generated by OpenCVE AI on September 20, 2026 at 08:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege SOAP Interface Vulnerability Enables Unauthorized Data Manipulation and Denial of Service
Weaknesses CWE-284
CWE-400

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged SOAP API Vulnerability in Oracle BI Publisher Allowing Data Modification and Denial of Service
Weaknesses CWE-285
CWE-399
CWE-862

Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged SOAP API Vulnerability in Oracle BI Publisher Allowing Data Modification and Denial of Service
Weaknesses CWE-285
CWE-399
CWE-862

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T14:03:20.992Z

Reserved: 2026-08-31T15:40:57.352Z

Link: CVE-2026-83308

cve-icon Vulnrichment

Updated: 2026-09-22T14:03:17.708Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:43.747

Modified: 2026-09-22T15:17:17.283

Link: CVE-2026-83308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:45:17Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-400

    Uncontrolled Resource Consumption