Description
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0 and 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthorized low‑privileged attacker who can reach the Oracle BI Publisher Web Service API can send crafted SOAP requests that bypass improperly enforced access controls (CWE‑284). The flaw permits the attacker to fully compromise the application, leading to unauthorized data disclosure, modification, and the ability to disrupt service availability.

Affected Systems

Oracle BI Publisher version 8.2.0.0.0 and 26.1.0.0.0, distributed by Oracle Corporation.

Risk and Exploitability

The vulnerability scores a CVSS 3.1 Base Score of 9.9, indicating critical severity. The EPSS score is less than 1 %, and the condition is not listed in the CISA KEV catalog, suggesting a low probability of widespread exploitation at present. However, the high potential impact on confidentiality, integrity, and availability, coupled with the low attack‑vector complexity and a single low‑privilege credential requirement, warrants prompt action, especially since scope changes may affect additional products.

Generated by OpenCVE AI on August 20, 2026 at 19:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle BI Publisher patch or update for versions 8.2.0.0.0 and 26.1.0.0.0 as released by Oracle.
  • Restrict access to the SOAP API by configuring firewall or network segmentation to accept connections only from trusted hosts or IP ranges.
  • Enable and enforce strong authentication and role‑based access controls on the BI Publisher service to prevent unauthorized API calls.
  • Monitor SOAP traffic for abnormal patterns and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 20, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*

Thu, 20 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Oracle BI Publisher SOAP API Access Control Bypass Leading to Remote Code Execution

Thu, 20 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Exploitable SOAP API in Oracle BI Publisher Enables Remote Compromise

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Exploitable SOAP API in Oracle BI Publisher Enables Remote Compromise

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Title Oracle BI Publisher SOAP API Remote Code Execution
Weaknesses CWE-284

Wed, 19 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Oracle BI Publisher SOAP API Remote Code Execution
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0 and 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle bi Publisher
CPEs cpe:2.3:a:oracle:bi_publisher:26.1.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bi Publisher
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Bi Publisher
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:04:16.718Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71059

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:05.743

Modified: 2026-08-24T15:54:41.170

Link: CVE-2026-71059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:30:05Z

Weaknesses