Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw lies within the BI Platform Security component of Oracle BI Publisher. An attacker who can reach the SOAP endpoints with low‑privileged credentials can send specially crafted requests that exploit a weakness, potentially compromising confidentiality, integrity, and availability of the entire BI Publisher instance. This vulnerability can enable a full takeover of the system. Based on the description, it is inferred that the attacker could perform actions typically protected by the application’s access controls, though the CVE text does not explicitly state a bypass.

Affected Systems

Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 are affected. These products are part of Oracle Analytics and are commonly deployed to deliver enterprise reporting. When exposed to a network, they present SOAP endpoints that can be accessed by attackers with low‑privileged credentials.

Risk and Exploitability

Earning a CVSS v3.1 base score of 8.8, the issue is classified as high severity. The EPSS score of less than 1% indicates a low current likelihood of exploitation, but because the flaw can be triggered remotely via standard SOAP traffic and only requires low privileges, the potential impact remains significant. The vulnerability is not listed in the CISA KEV catalog, so there are currently no known large‑scale attacks reported.

Generated by OpenCVE AI on September 20, 2026 at 08:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle BI Publisher security patch released in the 2026 update to address the authorization flaw.
  • Restrict SOAP endpoint access to trusted internal IP ranges or network segments using firewall rules or a reverse proxy to reduce exposure while the patch is deployed.
  • Enable comprehensive logging on the SOAP services and monitor for anomalous or repetitive requests that may indicate exploitation attempts, responding promptly to any detected activity.

Generated by OpenCVE AI on September 20, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege SOAP Exploit Enables Full Oracle BI Publisher Takeover

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low Privileged SOAP Exploit in Oracle BI Publisher Allows Full Takeover
Weaknesses CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low Privileged SOAP Exploit in Oracle BI Publisher Allows Full Takeover
Weaknesses CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-19T03:56:48.217Z

Reserved: 2026-08-31T15:40:57.352Z

Link: CVE-2026-83315

cve-icon Vulnrichment

Updated: 2026-09-17T12:59:59.835Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:44.520

Modified: 2026-09-19T04:17:57.320

Link: CVE-2026-83315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management