Junglewise Threat Intelligence

CVE-2026-60719: Oracle BI Publisher unauthorized data access in Web Service API

CVE-2026-60719 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle BI Publisher. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle BI Publisher, a reporting tool used for authoring and delivering business documents. An attacker with low-level user credentials can gain full access to sensitive business data, modify or delete critical records, and potentially disrupt the service. Because this flaw allows an attacker to move beyond the reporting tool itself, it may also pose a significant risk to other integrated corporate systems and data.

Technical details

This vulnerability affects the Web Service API component of Oracle BI Publisher within Oracle Analytics. It is classified as easily exploitable, requiring only low-privileged user authentication and network access via HTTP. The exploit results in a 'scope change' (CVSS S:C), meaning an attacker can impact components beyond the immediate security scope of BI Publisher. Successful exploitation grants unauthorized creation, deletion, or modification access to all accessible data, as well as the ability to cause a partial denial of service. Affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.

Affected products

  • Oracle BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats