Executive brief
Oracle BI Publisher is a reporting and analytics component used to generate and distribute business reports. A privilege escalation vulnerability in its security framework allows a high-privileged attacker with network access to completely compromise the system, potentially affecting other connected analytics products. Successful exploitation could enable full takeover of reporting infrastructure and unauthorized access to sensitive business intelligence data.
Technical details
This vulnerability exists in the BI Platform Security component of Oracle BI Publisher and permits privilege escalation via HTTP. The vulnerability is easily exploitable and requires only high-privileged user credentials and network access, with no user interaction needed. Successful exploitation grants complete control over the BI Publisher system with impacts extending to confidentiality, integrity, and availability; the scope change designation indicates potential compromise of downstream or related Oracle Analytics components. Patches are expected in Oracle's September 2026 security update cycle.
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed