Executive brief
Oracle BI Publisher is a business intelligence reporting tool used to create and distribute analytics reports across enterprises. A vulnerability in the Administration component allows an authenticated attacker with network access to completely compromise the system, potentially gaining full control over reports, user accounts, and sensitive business data.
Technical details
This privilege escalation vulnerability exists in the Administration component of Oracle BI Publisher and affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The flaw requires low-privilege authentication and HTTP network access but is considered difficult to exploit, requiring specific conditions to be met. Successful exploitation results in full compromise (confidentiality, integrity, and availability impact) and complete takeover of the BI Publisher system. The attack vector is network-based with no user interaction required. A patch is expected to be available through Oracle's regular security update cycle.
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-09-15: disclosed