CVE-2026-83284
Deferred Deferred - Pending Action

Denial of Service in Oracle BI Publisher

Vulnerability report for CVE-2026-83284, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-21

Assigner: Oracle

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-21
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
oracle bi_publisher 8.2.0.0.0
oracle bi_publisher 12.2.1.4.0
oracle bi_publisher 26.01.0.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle BI Publisher, part of Oracle Analytics. It allows an unauthenticated attacker with network access via SOAP to exploit the system. Successful exploitation can cause denial of service (DOS), unauthorized data modification, deletion, or insertion, and unauthorized data access.

Detection Guidance

This vulnerability can be detected by checking for exposed Oracle BI Publisher instances on your network. Look for open ports 80, 443, or 8000 where Oracle BI Publisher services might be running. Use network scanning tools like nmap to identify these services. Example command: nmap -p 80,443,8000 <target_IP>. Additionally, review logs for unusual SOAP requests or repeated crashes of the Oracle BI Publisher service.

Impact Analysis

The vulnerability can lead to system downtime due to crashes, unauthorized changes to data, or unauthorized access to sensitive information. This affects availability, integrity, and confidentiality of the Oracle BI Publisher system.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA due to unauthorized data access and modification risks. Unauthorized read, update, insert, or delete access to Oracle BI Publisher data may lead to violations of confidentiality and integrity requirements under these regulations. The potential for complete denial of service (DOS) also raises availability concerns.

Mitigation Strategies

Apply the latest security patches from Oracle for affected versions of BI Publisher (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0). Restrict network access to the SOAP interface of Oracle BI Publisher to trusted sources only. Monitor for unusual activity or crashes in the Oracle BI Publisher service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83284. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart