Junglewise Threat Intelligence

CVE-2026-83269: Oracle BI Publisher unauthenticated remote code execution

CVE-2026-83269 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is a reporting and publishing tool used within Oracle Analytics to create and distribute business intelligence reports. An unauthenticated network attacker can exploit this vulnerability to gain complete control over the BI Publisher system, potentially compromising confidential reports, modifying business data, and disrupting analytics operations.

Technical details

This vulnerability in Oracle BI Publisher's Platform Security component allows an unauthenticated attacker to achieve remote code execution via an HTTP-accessible interface. The attack requires no user interaction and is easily exploitable due to weak or missing authentication controls on a network-facing endpoint. Successful exploitation results in complete compromise of the Oracle BI Publisher instance, with impacts on confidentiality, integrity, and availability. Affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Patch availability from Oracle is expected as part of regular security updates.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats