Junglewise Threat Intelligence

CVE-2026-83308: Oracle BI Publisher authentication bypass in SOAP interface

CVE-2026-83308 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is a reporting and analytics component within Oracle Analytics that generates and distributes business reports. A low-privileged attacker with network access can exploit a vulnerability in the SOAP interface to modify, delete, or create critical data, or cause the service to crash entirely, disrupting reporting availability for the entire organization.

Technical details

A vulnerability in Oracle BI Publisher's BI Platform Security component allows a low-privileged, network-authenticated attacker to bypass security controls via the SOAP interface. The attack requires valid credentials but no elevated privileges. Successful exploitation results in unauthorized modification, deletion, or creation of critical data accessible to BI Publisher, and the ability to trigger denial-of-service conditions through repeated service crashes. The vulnerability affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Oracle has issued a security advisory (CVE-2026-83308) and patches are expected to be available through the standard Oracle security update cycle.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats