
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-83315 is a high-severity vulnerability in the Oracle BI Publisher product of Oracle Analytics, specifically affecting the BI Platform Security component. It affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability allows a low-privileged attacker with network access via SOAP to fully compromise Oracle BI Publisher. It was disclosed and patched on September 15, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 8.8 (High) (Oracle Advisory).
The vulnerability resides in the BI Platform Security component of Oracle BI Publisher and is exploitable over the network via the SOAP protocol. It is classified as an easily exploitable flaw requiring only low privileges and no user interaction, consistent with improper authorization or input validation weaknesses in the SOAP interface. The attack vector is network-based with low complexity, meaning no special conditions or race conditions are required for exploitation. Oracle has not publicly disclosed the specific CWE classification or detailed technical root cause, and no public proof-of-concept or technical write-up has been identified (Oracle Advisory).
Successful exploitation can result in a complete takeover of the Oracle BI Publisher instance, with high impact to confidentiality, integrity, and availability. An attacker could read sensitive business intelligence data, modify system configurations and reports, and disrupt service availability. Given BI Publisher's role in enterprise reporting and analytics, compromise could expose sensitive organizational data and potentially facilitate lateral movement within the enterprise environment (Oracle Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The vulnerability has an EPSS score of approximately 0.0048 (0.48%), indicating a relatively low near-term exploitation probability. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Oracle Advisory).
Oracle has released patches for all affected versions (8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0) as part of the September 2026 Critical Security Patch Update. Oracle strongly recommends applying the patch as soon as possible. As a temporary workaround, organizations can restrict network access to SOAP endpoints to only authorized users and systems, implement network segmentation to limit exposure of Oracle BI Publisher, and monitor SOAP traffic for anomalous activity. Disabling SOAP access entirely is an option if it is not required for business operations, though this may impact functionality (Oracle Advisory).
The vulnerability was included in Oracle's September 2026 CSPU, which addressed 673 new security patches across Oracle product families. The Australian Cyber Security Centre (AusCERT) published a bulletin (ASB-2026.0235) referencing this advisory. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-83315 has been identified beyond standard patch advisory coverage (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."