Executive brief
Oracle BI Publisher is a business intelligence reporting and publishing tool used to create, manage, and distribute reports and analytics across enterprises. A vulnerability in the BI Publisher Security component allows a low-privileged user with network access to gain unauthorized access to sensitive data or modify critical business intelligence reports and data. This could result in exposure of confidential analytics and business metrics to unauthorized personnel or corruption of trusted reporting infrastructure.
Technical details
A privilege escalation vulnerability exists in the Oracle BI Publisher Security component that allows authenticated attackers with low privileges to access or modify restricted data and reports. The vulnerability is network-exploitable via HTTP with low attack complexity and does not require user interaction. An attacker can leverage this flaw to read unauthorized BI Publisher data, insert or delete records, or access additional systems due to the scope change noted in the advisory. The vulnerability affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0; patched versions and mitigation guidance should be available from Oracle.
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed