Executive brief
Oracle BI Publisher is a reporting and analytics platform used by enterprises to create and distribute business intelligence reports. A vulnerability in its SOAP web service allows a low-privileged attacker with network access to gain complete control of the system, potentially exposing or modifying sensitive business reports and data.
Technical details
The vulnerability exists in the BI Platform Security component of Oracle BI Publisher and is exploitable via the SOAP interface. An attacker with low-privilege network access can trigger a privilege escalation attack with no user interaction required. Successful exploitation allows complete compromise of the BI Publisher instance, including read, write, and delete access to all data and functionality. The vulnerability affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed