Junglewise Threat Intelligence

CVE-2026-83312: Oracle BI Publisher unauthorized data access in E-Business Suite

CVE-2026-83312 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is a reporting and analytics component used within Oracle's E-Business Suite to generate and distribute business intelligence reports. A vulnerability allows attackers with low-level network access to gain unauthorized access to sensitive data stored in BI Publisher, potentially exposing critical business intelligence and customer information across the organization.

Technical details

A vulnerability in Oracle BI Publisher's E-Business Suite XDO component allows low-privileged authenticated users with network access via HTTP to read unauthorized data. The vulnerability has network attack vector with low complexity and does not require user interaction. Successful exploitation results in confidentiality impact—attackers can access critical data and all BI Publisher accessible data without authorization, though integrity and availability are not affected. The scope is changed, meaning compromise of BI Publisher can affect resources beyond the component itself. Patch availability has not been confirmed from the advisory text.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats