Executive brief
Oracle BI Publisher is a reporting and analytics tool used to generate and distribute business intelligence reports. A low-privileged attacker with network access can exploit an authentication or authorization flaw to gain unauthorized access to sensitive data, modify or delete critical reports and datasets, and partially disrupt service availability. The vulnerability affects multiple versions and requires no special user interaction to exploit.
Technical details
The vulnerability is an authorization bypass in the BI Platform Security component of Oracle BI Publisher. It allows a low-privileged attacker to escalate privileges and perform unauthorized operations including creation, deletion, and modification of critical data, as well as read access to all BI Publisher accessible data and partial denial of service. The attack vector is network-based via HTTP with low complexity and requires only low privileges (no admin role needed) and no user interaction. A fix or patch status has not been explicitly confirmed in the advisory.
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed