CVE-2026-60719
Oracle · BI Publisher
A vulnerability in the Oracle BI Publisher Web Service API allows low privileged, authenticated attackers to compromise data and cause partial denial of service via HTTP.
Executive summary
A critical vulnerability in Oracle BI Publisher allows authenticated attackers to manipulate sensitive data and impact system availability.
Vulnerability
The vulnerability resides in the Web Service API component. It allows a low privileged attacker with network access to perform unauthorized creation, deletion, or modification of critical data, as well as trigger a partial denial of service.
Business impact
Successful exploitation poses a severe risk to data integrity and business continuity. With a CVSS score of 9.9, this vulnerability enables attackers to bypass standard access controls, potentially resulting in the loss of proprietary information or the disruption of analytical reporting services. The scope change indicates that impacts may extend beyond the BI Publisher platform to integrated systems.
Remediation
Immediate Action: Apply the relevant patches provided in the July 2026 Oracle Critical Patch Update advisory.
Proactive Monitoring: Review web service access logs for unusual patterns or high frequencies of API calls originating from low-privileged accounts.
Compensating Controls: Implement strict network segmentation and ensure that Web Application Firewalls are configured to inspect and filter traffic directed at the BI Publisher Web Service API.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS score of 9.9, organizations must prioritize the application of the July 2026 security patches. Administrators should immediately identify instances of BI Publisher within their environment and schedule maintenance windows to ensure these updates are deployed without delay.