Junglewise Threat Intelligence

CVE-2026-83314: Oracle BI Publisher privilege escalation in Web Service API

CVE-2026-83314 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is a reporting and analytics tool within Oracle Analytics. A vulnerability in its Web Service API allows low-privileged authenticated users with network access to bypass security controls, enabling them to modify or delete critical business reports and data, or crash the service entirely. This could result in data loss, service outages, and unauthorized access to sensitive analytics.

Technical details

An easily exploitable integrity and availability vulnerability exists in the Web Service API component of Oracle BI Publisher (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0). The vulnerability is reachable via SOAP protocol and requires low privilege authentication and network access, with no user interaction required. An attacker can exploit this flaw to create, delete, or modify critical data or cause denial of service through repeated crashes of the Oracle BI Publisher service. Oracle has assigned a CVSS 3.1 score of 8.1 (High severity) reflecting high integrity and availability impacts. Patch availability status is not confirmed from the provided advisory text.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats