Executive brief
Oracle BI Publisher, a reporting and document generation solution within Oracle Analytics, contains a critical security flaw in its security component. An unauthorized person can use this vulnerability over the internet to gain full control of the system. This could lead to the theft of sensitive business data, unauthorized modification of reports, or a total shutdown of the reporting service.
Technical details
A critical vulnerability exists in the BI Platform Security component of Oracle BI Publisher (versions 8.2.0.0.0 and 12.2.1.4.0). The flaw is categorized as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation can result in a complete takeover of the Oracle BI Publisher instance, impacting confidentiality, integrity, and availability. While the specific CWE is not provided in the advisory, the CVSS vector indicates a low-complexity, remote attack requiring no user interaction or privileges. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD