Junglewise Threat Intelligence

CVE-2026-83305: Oracle BI Publisher authentication bypass in BI Platform Security

CVE-2026-83305 · Severity: high · CVSS 8.6 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is an enterprise analytics and reporting platform used to access and visualize business data. A vulnerability in the BI Platform Security component allows attackers to bypass authentication without credentials and gain unauthorized access to sensitive data, modify or delete information, and degrade system availability.

Technical details

This is an authentication bypass vulnerability in the BI Platform Security component of Oracle BI Publisher. The flaw allows unauthenticated attackers to access the application via HTTP without providing valid credentials. The vulnerability is easily exploitable due to minimal attack complexity and requires no user interaction or special privileges. Successful exploitation enables unauthorized read access to all BI Publisher data, limited modification/deletion of accessible data, and partial denial of service. Patch availability is not documented in the provided advisory; contact Oracle for remediation guidance.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats