Executive brief
Oracle BI Publisher, a reporting and document generation tool within Oracle Analytics, contains a security vulnerability in its XML Services component. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could lead to a significant exposure of confidential reports and organizational information managed within the system.
Technical details
An information disclosure vulnerability exists in the XML Services component of Oracle BI Publisher (part of Oracle Analytics). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended confidentiality restrictions, resulting in unauthorized access to critical data or complete access to all data accessible by the BI Publisher service. The vulnerability affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and security alert.