Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker can exploit the Web Service API of Oracle BI Publisher through an HTTP connection to change, delete, or create data, gain full read access to all data, and cause a partial denial of service. The flaw is rooted in multiple weak points: improper input validation (CWE‑20), missing or insecure authorization checks (CWE‑269, CWE‑284, CWE‑285), denial‑of‑service conditions (CWE‑400) and data leakage through reduced access controls (CWE‑639). The CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L indicates that the attacker needs only network connectivity, no user interaction, and benefits from a compromised confidentiality, integrity, and the availability of the system.

Affected Systems

The affected product is Oracle BI Publisher (Oracle Analytics) provided by Oracle Corporation. Vulnerable versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.

Risk and Exploitability

With a CVSS base score of 9.9 the vulnerability is classed as critical, yet the EPSS score of less than 1% suggests a very low likelihood that it is currently being exploited. The vulnerability is not listed in CISA’s KEV catalog, but because it has a scope change it may impact additional products if the attacker gains further control. The attack path is a simple network‑based request to a Web Service API; no privileged credentials or user interaction are required, making it quickly exploitable if the system is exposed.

Generated by OpenCVE AI on August 12, 2026 at 12:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for BI Publisher as published in the Oracle CPU July 2026 advisory
  • Restrict HTTP access to the BI Publisher Web Service API to trusted hosts or VPN only, reducing surface for network‑based attackers
  • Enable logging and monitor for anomalous API activity to detect potential exploitation attempts

Generated by OpenCVE AI on August 12, 2026 at 12:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Remote API Exploitation Grants Unauthorized Data Access in Oracle BI Publisher
Weaknesses CWE-285
CWE-639

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Remote API Exploitation Grants Unauthorized Data Access in Oracle BI Publisher
Weaknesses CWE-285
CWE-639

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Remote API Vulnerability That Allows Unauthorized Data Modification in Oracle BI Publisher
Weaknesses CWE-284
CWE-863

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Remote API Vulnerability That Allows Unauthorized Data Modification in Oracle BI Publisher
Weaknesses CWE-284
CWE-863

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Exploitable Vulnerability in Oracle BI Publisher Web Service API
Weaknesses CWE-269
CWE-285

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Exploitable Vulnerability in Oracle BI Publisher Web Service API
Weaknesses CWE-269
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:09:09.345Z

Reserved: 2026-07-08T15:51:55.582Z

Link: CVE-2026-60719

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:12.250

Modified: 2026-08-03T16:46:47.857

Link: CVE-2026-60719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:15:04Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-400

    Uncontrolled Resource Consumption