
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-83314 is an authorization bypass vulnerability in the Oracle BI Publisher Web Service API component of Oracle Analytics. It affects Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability was disclosed and patched on September 15, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 8.1 (High) (Oracle Advisory).
The vulnerability is classified as an authorization bypass (CWE category: improper authorization) in the SOAP-based Web Service API of Oracle BI Publisher. A low-privileged attacker with network access can send crafted SOAP requests to the vulnerable API endpoint, bypassing authorization controls to perform unauthorized data operations or trigger denial-of-service conditions. No authentication bypass is required — the attacker only needs a valid low-privileged account and network access to the SOAP interface. No public technical write-ups or proof-of-concept code have been identified at this time (Oracle Advisory).
Successful exploitation allows a low-privileged attacker to perform unauthorized creation, deletion, or modification of critical data accessible to Oracle BI Publisher, as well as cause the service to hang or crash repeatedly, resulting in a complete denial of service. There is no confidentiality impact (data exfiltration is not a direct consequence), but the integrity and availability of all BI Publisher-accessible data and the service itself are fully compromised. Organizations relying on Oracle BI Publisher for business intelligence reporting could face significant operational disruption and data integrity loss (Oracle Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The vulnerability is easily exploitable (low attack complexity, no user interaction required) by any low-privileged user with network access via SOAP, making it a relatively accessible target once an attacker has valid credentials. The EPSS score is approximately 0.43%, indicating a low but non-negligible probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified (Oracle Advisory).
Oracle has released a security patch for CVE-2026-83314 as part of the September 15, 2026 Critical Security Patch Update, covering Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Organizations should apply the patch immediately via the Oracle Analytics patch availability documentation. As a temporary workaround prior to patching, Oracle recommends restricting network access to the SOAP Web Service API to trusted clients only and implementing network segmentation to limit exposure. Removing unnecessary low-privileged user access to the SOAP API can also reduce risk, though Oracle cautions that workarounds may break application functionality and are not long-term solutions (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."