Junglewise Threat Intelligence

CVE-2026-83313: Oracle BI Publisher authorization bypass in BI Platform Security

CVE-2026-83313 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is a reporting and analytics component used to create, distribute, and manage business intelligence reports in Oracle Analytics. A vulnerability in its security layer allows an authenticated user with low privileges to gain unauthorized access to sensitive data or complete access to all BI Publisher data through network-based exploitation, potentially compromising the confidentiality of critical business intelligence across the organization.

Technical details

This vulnerability resides in the BI Platform Security component of Oracle BI Publisher. It is an authorization weakness that allows a low-privileged attacker with valid network access via HTTP to escalate access and retrieve unauthorized data. The attack vector is network-based and does not require user interaction; however, authentication is required (the attacker must possess low-privilege credentials). Successful exploitation results in unauthorized disclosure of critical data or complete data exfiltration from BI Publisher. The vulnerability affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Oracle's patch status and timeline are not yet publicly confirmed.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats