Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Modification
Action: Apply Patch
AI Analysis

Impact

A flaw in the BI Platform Security component of Oracle BI Publisher allows an attacker with low system privileges and network access to exploit the SOAP interface. By doing so the attacker can gain unauthorized read access to critical data and, in some cases, execute write operations - update, insert, or delete - on data exposed by the application. The vulnerability is characterized by an AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N vector, indicating that network-based exploitation leads to a significant impact on confidentiality and a moderate impact on integrity.

Affected Systems

The affected product is Oracle BI Publisher, part of Oracle Analytics. Supported versions that are vulnerable are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Any deployment using these versions is susceptible to the described exploitation path.

Risk and Exploitability

The CVSS base score of 8.5 reflects a high level of severity, while the EPSS score of less than 1% suggests a low probability of current exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, yet the potential for scope change means that related Oracle Analytics products could also be impacted. Attacks require only low privileged credentials and SOAP access, making the attack vector readily achievable for adversaries with network presence, though the overall exploitation likelihood remains relatively low.

Generated by OpenCVE AI on September 20, 2026 at 08:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a version of Oracle BI Publisher that includes the fix or a relevant patch from Oracle.
  • If an upgrade is not immediately possible, restrict SOAP access to trusted IP ranges and enforce strict authentication for all users accessing the service.
  • Implement network segmentation and monitoring to detect anomalous SOAP traffic that could indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 08:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Oracle BI Publisher SOAP Interface Vulnerability Enables Unauthorized Data Access
Weaknesses CWE-284

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via SOAP in Oracle BI Publisher
Weaknesses CWE-284

Wed, 16 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via SOAP in Oracle BI Publisher
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-26T23:12:26.889Z

Reserved: 2026-08-31T15:40:57.352Z

Link: CVE-2026-83311

cve-icon Vulnrichment

Updated: 2026-09-18T18:08:40.897Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:44.080

Modified: 2026-09-27T00:16:34.810

Link: CVE-2026-83311

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:15:16Z

Weaknesses