Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle BI Publisher allows an unauthenticated attacker to remotely take over the application. The weakness, stemming from inadequate access control (CWE‑284), enables execution of arbitrary code through standard HTTP channels, leading to full compromise of confidentiality, integrity, and availability for the affected instance.

Affected Systems

Oracle BI Publisher versions 8.2.0.0.0 and 12.2.1.4.0 are impacted. These versions are part of Oracle Analytics and are widely deployed in enterprise environments.

Risk and Exploitability

The CVSS 3.1 score of 9.8 indicates critical severity. Although the EPSS score is below 1%, the vulnerability is exploitable with network access and no credentials, and is not currently listed in CISA KEV. Attackers could leverage the HTTP interface to trigger the exploit, potentially gaining full control of the BI Publisher server.

Generated by OpenCVE AI on August 4, 2026 at 17:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Security Patch for CVE-2026-60173
  • Enforce authentication by enabling HTTPS and requiring login credentials prior to accessing BI Publisher
  • Implement role-based access controls and enforce least‑privilege permissions on BI Publisher, addressing the access‑control weakness in CWE‑284
  • Restrict network exposure by limiting HTTP/HTTPS access to trusted IP ranges or applying a firewall rule that blocks all external traffic to the BI Publisher port

Generated by OpenCVE AI on August 4, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover of Oracle BI Publisher via HTTP

Mon, 03 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle BI Publisher via HTTP
Weaknesses CWE-287

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle BI Publisher via HTTP
Weaknesses CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:05:14.718Z

Reserved: 2026-07-08T15:51:40.517Z

Link: CVE-2026-60173

cve-icon Vulnrichment

Updated: 2026-07-23T16:24:42.456Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses