Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle BI Publisher is vulnerable through its XML Services component, allowing an attacker with limited local privileges who can reach the HTTP interface to gain unauthorized access to any data the publisher holds. The flaw can be exploited easily, exposing sensitive reports, configuration files, or other stored information, and in the worst case can provide complete control over all data available through Oracle BI Publisher.

Affected Systems

Version 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0 of Oracle BI Publisher are affected. These versions are used in Oracle Analytics deployments that expose reported data through web services.

Risk and Exploitability

The CVSS v3.1 score of 6.5 indicates moderate severity, with a high confidentiality impact and no impact to integrity or availability. The EPSS score of less than 1% suggests exploitation is unlikely in the near term and the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is remote, via HTTP to the XML Services endpoint, and the exploit requires only low privileged access.

Generated by OpenCVE AI on August 4, 2026 at 03:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Oracle Analytics security update from the July 2026 CPU release (https://www.oracle.com/security-alerts/cpujul2026.html)
  • Restrict HTTP access to Oracle BI Publisher to trusted IP ranges using firewalls or subnet isolation
  • Disable XML Services or restrict its usage to authenticated users when the functionality is not required

Generated by OpenCVE AI on August 4, 2026 at 03:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Oracle BI Publisher XML Services Unauthorized Data Access Vulnerability

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Oracle BI Publisher XML Services Unauthorized Data Access Vulnerability

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Public XML Services Remote Data Access Vulnerability in Oracle BI Publisher
Weaknesses CWE-284

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Public XML Services Remote Data Access Vulnerability in Oracle BI Publisher
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:20:32.773Z

Reserved: 2026-07-08T15:51:55.577Z

Link: CVE-2026-60673

cve-icon Vulnrichment

Updated: 2026-07-24T19:20:28.425Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:08.213

Modified: 2026-08-06T15:28:23.510

Link: CVE-2026-60673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor