CVE-2026-83314
Received Received - Intake

Oracle BI Publisher Web Service API DoS and Data Manipulation

Vulnerability report for CVE-2026-83314, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-18

Assigner: Oracle

Description

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-18
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
oracle bi_publisher 8.2.0.0.0
oracle bi_publisher 12.2.1.4.0
oracle bi_publisher 26.01.0.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle BI Publisher, part of Oracle Analytics. It allows a low-privileged attacker with network access to exploit the Web Service API via SOAP requests. The attacker can gain unauthorized access to modify, delete, or create critical data within Oracle BI Publisher. Additionally, the vulnerability can cause the system to crash repeatedly or become unavailable entirely.

Detection Guidance

This vulnerability affects Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Detection involves checking for these versions and monitoring for unauthorized SOAP requests targeting the Web Service API. Inspect network traffic for unusual SOAP messages to Oracle BI Publisher endpoints. Verify if low-privileged users have access to SOAP interfaces without proper restrictions.

Impact Analysis

If exploited, this vulnerability could lead to unauthorized data manipulation, deletion, or creation within Oracle BI Publisher. It may also cause system downtime due to crashes, disrupting business operations. Attackers with low privileges could escalate their access to compromise sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's data integrity and confidentiality requirements. For HIPAA, it may compromise protected health information integrity and availability. Non-compliance risks include legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Apply the latest security patches from Oracle for Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Restrict network access to the SOAP interface and limit privileges for users to the minimum required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83314. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart