Junglewise Threat Intelligence

CVE-2026-83310: Oracle BI Publisher authorization bypass in BI Platform Security

CVE-2026-83310 · Severity: high · CVSS 8.7 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is a critical component of Oracle Analytics used to create and distribute business reports and dashboards. A vulnerability in the BI Platform Security module allows a low-privileged user with network access to bypass authorization controls and gain unauthorized access to create, delete, or modify sensitive business data. The attack requires user interaction (such as a victim clicking a malicious link) but can impact the confidentiality and integrity of all reports and data accessible through the platform.

Technical details

This is an authorization bypass vulnerability in the BI Platform Security component of Oracle BI Publisher. The vulnerability is easily exploitable via HTTP by a low-privileged network-adjacent attacker and requires user interaction from a victim to succeed. The scope is marked as changed, indicating that while the vulnerability exists in BI Publisher, successful exploitation can impact additional Oracle products or systems. An attacker can gain unauthorized create, read, modify, or delete access to critical business data and reports. Patches are expected from Oracle as part of their standard security release cycle.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats