A vulnerability in the Oracle BI Publisher Web Service API allows low privileged, authenticated attackers to compromise data and cause partial denial...
Description
A vulnerability in the Oracle BI Publisher Web Service API allows low privileged, authenticated attackers to compromise data and cause partial denial of service via HTTP.
AI Analyst Comment
Remediation
Update Oracle Oracle BI Publisher to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Oracle
PRODUCT: BI Publisher
AFFECTED_VERSIONS: 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A vulnerability in the Oracle BI Publisher Web Service API allows low privileged, authenticated attackers to compromise data and cause partial denial of service via HTTP.
Executive Summary:
A critical vulnerability in Oracle BI Publisher allows authenticated attackers to manipulate sensitive data and impact system availability.
Vulnerability Details
CVE-ID: CVE-2026-60719
Affected Software: Oracle BI Publisher
Affected Versions: 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
Vulnerability: The vulnerability resides in the Web Service API component. It allows a low privileged attacker with network access to perform unauthorized creation, deletion, or modification of critical data, as well as trigger a partial denial of service.
Business Impact
Successful exploitation poses a severe risk to data integrity and business continuity. With a CVSS score of 9.9, this vulnerability enables attackers to bypass standard access controls, potentially resulting in the loss of proprietary information or the disruption of analytical reporting services. The scope change indicates that impacts may extend beyond the BI Publisher platform to integrated systems.
Remediation Plan
Immediate Action: Apply the relevant patches provided in the July 2026 Oracle Critical Patch Update advisory.
Proactive Monitoring: Review web service access logs for unusual patterns or high frequencies of API calls originating from low-privileged accounts.
Compensating Controls: Implement strict network segmentation and ensure that Web Application Firewalls are configured to inspect and filter traffic directed at the BI Publisher Web Service API.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 21, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is considered highly exploitable given the low requirements for attacker privileges and network access.
Analyst Recommendation
Given the critical CVSS score of 9.9, organizations must prioritize the application of the July 2026 security patches. Administrators should immediately identify instances of BI Publisher within their environment and schedule maintenance windows to ensure these updates are deployed without delay.