cve-2026-83305
HIGH CVSS 8.6 opencveVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
- Published
- 2026-09-15 20:18 UTC
- Last Modified
- 2026-09-22
CVSS details not available.
No product information available.
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
mitre | ||
| 3.1 | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
nvd | ||
| 3.1 | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
opencve |
No references available.
No linked vulnerabilities found.
{
"cve": "CVE-2026-83305",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "8.2.0.0.0"
}
},
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "12.2.1.4.0"
}
},
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "26.01.0.0.0"
}
}
],
"enrichment": {
"confidence": 95.0,
"confidence_source": "inferred",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Oracle BI Publisher",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "bi_publisher",
"vendor": "oracle"
}
],
"created": "2026-09-16T13:15:14.781162+00:00",
"updated": "2026-09-22T16:15:08.124135+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$bi_publisher"
],
"weaknesses": [
"CWE-200",
"CWE-284",
"CWE-285",
"CWE-306"
]
},
"epss": {
"score": 0.00358
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*"
],
"created": "2026-09-15T20:04:53.880000+00:00",
"description": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.6,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/83xxx/CVE-2026-83305.json",
"references": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"title": null,
"updated": "2026-09-22T14:00:52.677000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$bi_publisher"
],
"weaknesses": []
},
"nvd": {
"cpes": [],
"created": "2026-09-15T20:18:43.423000+00:00",
"description": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.6,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-83305.json",
"references": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"title": null,
"updated": "2026-09-22T14:17:16.350000+00:00",
"vendors": [],
"weaknesses": [
"CWE-306"
]
},
"opencve": {
"changes": [
{
"created": "2026-09-15T20:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$bi_publisher"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$bi_publisher"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 8.6,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "6c70450b-d9c6-4e16-8332-e50650338e8e"
},
{
"created": "2026-09-16T22:45:00+00:00",
"data": [
{
"details": {
"new": "Unauthenticated HTTP Access Allows Unauthorized Data Manipulation and Partial Denial of Service in Oracle BI Publisher",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-284",
"CWE-287"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "833d2cc4-3a25-43ff-bf50-e9db2dbc9b33"
},
{
"created": "2026-09-18T21:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Unauthenticated HTTP Access Allows Unauthorized Data Manipulation and Partial Denial of Service in Oracle BI Publisher"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-284",
"CWE-287"
]
},
"type": "weaknesses"
}
],
"id": "2940be60-c0c3-47d2-a996-21ecaff38ca3"
},
{
"created": "2026-09-20T08:30:00+00:00",
"data": [
{
"details": {
"new": "Unauthenticated HTTP Remote Access Leads to Data Compromise and Partial Denial of Service in Oracle BI Publisher",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-200",
"CWE-284",
"CWE-285"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "73eb78a1-261b-42b5-bd5b-4864e37a54ff"
},
{
"created": "2026-09-22T14:30:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-306"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "091e55af-7835-46ba-b999-918a0a18a647"
},
{
"created": "2026-09-22T16:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Unauthenticated HTTP Remote Access Leads to Data Compromise and Partial Denial of Service in Oracle BI Publisher"
},
"type": "title"
}
],
"id": "a9260145-51bb-406c-9a81-2dd87410d03e"
},
{
"created": "2026-09-23T15:30:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "7ecd9361-0469-49c6-b549-91cbf2882cad"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*"
],
"providers": [
"mitre"
]
},
"created": {
"data": "2026-09-15T20:04:53.880000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 8.6,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00358
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": null,
"provider": null
},
"updated": {
"data": "2026-09-22T16:15:08.124135+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$bi_publisher"
],
"providers": [
"mitre",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-200",
"CWE-284",
"CWE-285",
"CWE-306"
],
"providers": [
"nvd",
"vulnrichment",
"enrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-09-15T20:04:53.880000+00:00",
"description": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-09-22T14:00:40.845000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/83xxx/CVE-2026-83305.json",
"weaknesses": [
"CWE-306"
]
}
}