Executive brief
Oracle BI Publisher is a reporting and analytics tool used by organizations to create, distribute, and access business reports. An unauthenticated attacker can send a specially crafted SOAP request over the network to crash the service or read, modify, or delete sensitive report data, causing operational disruption and potential data compromise.
Technical details
This is an unauthenticated remote code/access vulnerability in Oracle BI Publisher's SOAP interface (BI Platform Security component). The vulnerability requires no user interaction and is easily exploitable via network-accessible SOAP endpoints. An attacker can trigger denial of service (application hang or crash), unauthorized data manipulation (insert/update/delete), and unauthorized information disclosure. The affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 of Oracle BI Publisher within Oracle Analytics.
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed