Junglewise Threat Intelligence

CVE-2026-83319: Oracle BI Publisher unauthorized data access in Web Service API

CVE-2026-83319 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

Oracle BI Publisher is a reporting and analytics component used within Oracle Analytics to create and distribute business reports. A flaw in its Web Service API allows authenticated users with low privileges to access sensitive data they should not be able to view, potentially compromising confidential business information across multiple connected systems.

Technical details

The vulnerability is an unauthorized access flaw in the Oracle BI Publisher Web Service API (SOAP interface) affecting version 12.2.1.4.0. It allows a low-privileged, authenticated attacker with network access to the SOAP endpoint to bypass authorization controls and gain access to critical data. The vulnerability does not enable data modification or denial of service, but achieves high confidentiality impact and has scope change, meaning it can affect other Oracle products. No patch information is currently available in the advisory.

Affected products

  • Oracle BI Publisher 12.2.1.4.0

Timeline

  • 2026-09-15: disclosed

References

Related threats