CVE-2026-83268
CRITICAL · 9.1Fresh CVSS-driven chatter only; no PoC, advisory, or exploitation reports yet.
What: Oracle BI Publisher (Analytics BI Platform Security) privilege escalation allowing network-accessible takeover; versions 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 affected. CVSS 9.1 CRITICAL.
Why it matters: Published 24 hours ago, not yet KEV-listed. CVSS 9.1 reflects high impact (C/I/A), but requires high-privilege attacker with network access—exploitation surface is narrower than headline severity suggests. No public PoC, vendor advisory, or defender triage reports visible in social chatter; posts are automated feeds reposting NVD metadata.
Where it's seen: Bluesky mentions are generic CVE feed republishes; no vendor patch status, exploit code, or real-world signal. Noise only.
RISK: HIGH — Oracle critical component; scope change to other products; but requires pre-existing high-privilege access.
Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- High
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High