Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and access
Action: Immediate Patch
AI Analysis

Impact

Oracle BI Publisher contains a weakness in its BI Platform Security component that enables a low‑privileged attacker with network access to compromise the system over HTTP. When successfully exploited, an attacker can create, delete, or modify critical data that is normally protected, allowing unauthorized access to all data available through the publisher. The flaw requires the attacker to be able to interact with a user other than themselves in order to gain the necessary privileges, indicating that user interaction is a prerequisite for exploitation.

Affected Systems

Oracle Corporation’s BI Publisher product is affected in the following versions: 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.

Risk and Exploitability

The identified vulnerability carries a high severity score of 8.7 on the CVSS 3.1 scale, with a low exploit probability indicated by an EPSS score of less than 1 %. Although it is not listed in CISA’s KEV catalog, the high impact on confidentiality and integrity means that any successful attack can lead to significant data tampering or disclosure. The attack can be performed over the network via HTTP from any low‑privileged host, but requires human interaction – typically an injected request or malicious link clicked by an authorized user – and could also affect other Oracle Analytics components due to the scope change.

Generated by OpenCVE AI on September 18, 2026 at 15:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Oracle BI Publisher to a non‑affected release or apply the vendor’s patch that addresses the security flaw.
  • Restrict HTTP access to the BI Publisher service by limiting connections to trusted IP ranges or implementing a firewall rule that blocks external requests.
  • Configure the application to enforce stricter authentication and authorization policies, ensuring that only users with explicit privileges can create, modify, or delete data, and monitor for any anomalous activity suspicious of exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Modification in Oracle BI Publisher via Low‑Privilege HTTP Exploit
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:49.054Z

Reserved: 2026-08-31T15:40:57.352Z

Link: CVE-2026-83310

cve-icon Vulnrichment

Updated: 2026-09-18T18:16:05.049Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:43.967

Modified: 2026-09-18T19:16:55.070

Link: CVE-2026-83310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:45:10Z

Weaknesses