Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidential data exposure
Action: Immediate patch
AI Analysis

Impact

A flaw in the Web Service API of Oracle BI Publisher allows a low‑privileged attacker who can reach the SOAP endpoint over the network to gain unauthorized access to highly confidential data. The vulnerability’s CVSS vector shows high confidentiality impact while only low system privileges are required, indicating that the attacker can obtain complete data access.

Affected Systems

Oracle BI Publisher version 12.2.1.4.0, a component of Oracle Analytics.

Risk and Exploitability

The CVSS base score of 7.7 combined with an EPSS value below 1% indicates that the vulnerability is exploitable yet the current likelihood of widespread exploitation is low. Because the flaw lies in access control, a simple SOAP request from an attacker who can reach the service will expose all data that the service can deliver, potentially affecting ancillary Oracle Analytics products. The vulnerability is not yet listed in CISA’s KEV catalog, but the potential for cross‑product impact warrants prompt attention.

Generated by OpenCVE AI on September 18, 2026 at 18:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to a version that eliminates the access‑control flaw in Oracle BI Publisher.
  • Restrict the SOAP service to trusted IP ranges or network segments using firewall or segmentation controls.
  • Enforce least‑privilege for API callers, review and audit API access logs, and disable the SOAP endpoint if it is not required for business operations.

Generated by OpenCVE AI on September 18, 2026 at 18:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege SOAP API Vulnerability in Oracle BI Publisher
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege SOAP API Vulnerability in Oracle BI Publisher
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T16:22:03.623Z

Reserved: 2026-08-31T15:40:57.352Z

Link: CVE-2026-83319

cve-icon Vulnrichment

Updated: 2026-09-18T16:21:50.337Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:44.970

Modified: 2026-09-18T17:17:02.260

Link: CVE-2026-83319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:30:12Z

Weaknesses