Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Full System Compromise of Oracle BI Publisher
Action: Immediate Patch
AI Analysis

Impact

of Oracle BI Publisher and permits a low‑privileged attacker with network access to HTTP to compromise the application. Successful exploitation can lead to complete takeover of the system, resulting in loss of confidentiality, integrity, and availability of data. The weakness is a form of unauthorized access that allows an attacker to bypass authentication controls.

Affected Systems

Oracle Corporation: Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 are affected.

Risk and Exploitability

The CVSS 3.1 base score is 7.5, indicating substantial impact. EPSS score is less than 1 %, suggesting low current exploitation probability, but the vulnerability is not listed in CISA KEV. Although the attack vector is indirect (network via HTTP), the attacker only needs low privileges and no user interaction, which makes the threat realistic against exposed installations. Mitigation remains critical because a successful attack gives the attacker full control.

Generated by OpenCVE AI on September 20, 2026 at 08:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued security patch for Oracle BI Publisher.
  • Ensure the Administration component is not exposed to the public internet; restrict access to trusted internal networks or VPN.
  • Validate that existing authentication and authorization controls are correctly configured; remove any default or unnecessary administrative accounts.
  • Monitor logs for anomalous HTTP activity targeting the Administration endpoints and enable intrusion detection if possible.

Generated by OpenCVE AI on September 20, 2026 at 08:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Access Vulnerability in Oracle BI Publisher Administration

Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Oracle BI Publisher Administration Component Vulnerability Enables Takeover
Weaknesses CWE-286

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Oracle BI Publisher Administration Component Vulnerability Enables Takeover
Weaknesses CWE-286

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-19T03:56:36.752Z

Reserved: 2026-08-31T15:40:57.352Z

Link: CVE-2026-83318

cve-icon Vulnrichment

Updated: 2026-09-17T12:59:56.062Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:44.860

Modified: 2026-09-19T04:17:59.600

Link: CVE-2026-83318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management