Oracle disclosed CVE-2026-83268, a critical vulnerability in Oracle BI Publisher's BI Platform Security component that, per Oracle's own assessment, allows a high-privileged, network-based attacker to fully take over the product and reach beyond it into adjacent systems.
What Is It
CVE-2026-83268 is a vulnerability in the Oracle BI Publisher product of Oracle Analytics, specifically the BI Platform Security component. Oracle describes it as easily exploitable: an attacker with high privileges and network access over HTTP can compromise Oracle BI Publisher without any user interaction. According to Oracle, successful exploitation can result in complete takeover of the BI Publisher instance.
The flaw carries a CVSS 3.1 base score of 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, high privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.
Why It Matters
The scope is marked as CHANGED. Oracle states that while the vulnerability lives in Oracle BI Publisher, attacks may significantly impact additional products. That scope change is what pushes an otherwise privilege-gated bug into critical territory: on Oracle's reading, a compromise would not stay contained to the reporting platform.
BI Publisher sits on top of enterprise reporting data, and a full takeover would mean an attacker controls the confidentiality, integrity, and availability of that platform and can extend pressure onto systems that trust it.
The privileges-required rating is HIGH, so this is not an unauthenticated internet drive-by. It is a strong escalation and lateral-movement primitive for anyone who already holds an elevated account; insider, contractor, or an attacker who has already harvested credentials.
There is no CISA KEV entry in the supplied source material for CVE-2026-83268, so active exploitation is not confirmed at this time.
What's Vulnerable
Oracle BI Publisher (Oracle Corporation), supported versions:
- 8.2.0.0.0
- 12.2.1.4.0
- 26.01.0.0.0
No CPE match data was published with the record.
Patch Status
The CVE was published 2026-09-15 with a status of "Received," meaning NVD analysis is still pending. Oracle's fix is delivered through a September 2026 Oracle advisory, which is the single reference attached to the record.
That reference is ambiguous in the source data, and administrators should treat it with care. The CVE record labels it as an Oracle Security Alert, while the advisory is elsewhere described as a September 2026 Critical Patch Update; two distinct Oracle publication types with separate release processes. The attached URL (cspusep2026.html) matches neither Oracle's Security Alert nor its Critical Patch Update URL convention, so it cannot be used to settle which document is meant. Administrators should locate the correct September 2026 advisory through Oracle's security alerts index rather than trusting the linked path or the label in the record.
Those running any of the three affected versions should apply Oracle's published update once the correct advisory is identified. No CISA-mandated remediation deadline exists in the supplied data.
Sources
- NVD, CVE-2026-83268: https://nvd.nist.gov/vuln/detail/CVE-2026-83268
- Oracle September 2026 advisory, as referenced in the CVE record; labeled a Security Alert in the record but described elsewhere as a Critical Patch Update; URL unverified against Oracle's advisory index: https://www.oracle.com/security-alerts/cspusep2026.html