Junglewise Threat Intelligence

CVE-2026-83284: Oracle BI Publisher SOAP request denial of service and data access

CVE-2026-83284 · Severity: high · CVSS 8.6 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is a reporting and analytics tool used by organizations to create, distribute, and access business reports. An unauthenticated attacker can send a specially crafted SOAP request over the network to crash the service or read, modify, or delete sensitive report data, causing operational disruption and potential data compromise.

Technical details

This is an unauthenticated remote code/access vulnerability in Oracle BI Publisher's SOAP interface (BI Platform Security component). The vulnerability requires no user interaction and is easily exploitable via network-accessible SOAP endpoints. An attacker can trigger denial of service (application hang or crash), unauthorized data manipulation (insert/update/delete), and unauthorized information disclosure. The affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 of Oracle BI Publisher within Oracle Analytics.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats