Junglewise Threat Intelligence

CVE-2026-83311: Oracle BI Publisher privilege escalation in SOAP interface

CVE-2026-83311 · Severity: high · CVSS 8.5 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher, a component of Oracle Analytics that provides business intelligence and reporting capabilities, contains a security vulnerability in its SOAP web service interface. A low-privileged attacker with network access can exploit this flaw to gain unauthorized access to sensitive business data and modify or delete critical information stored within the system. This vulnerability could impact data confidentiality and integrity across the entire analytics platform.

Technical details

The vulnerability exists in the BI Platform Security component of Oracle BI Publisher and is exploitable via the SOAP protocol. A low-privileged attacker with network access can leverage this easily exploitable flaw to perform unauthorized data access, modification, or deletion. The vulnerability demonstrates scope change behavior, meaning successful exploitation can impact other Oracle Analytics products beyond BI Publisher itself. No special authentication bypass or user interaction is required—only low-level credentials and network connectivity to the SOAP endpoint. Patches are expected from Oracle for affected versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats