CVE-2026-60173
A critical flaw in Oracle BI Publisher allows anyone on the network to take full control of the application without needing a password. The weakness can be triggered over standard HTTP traffic and gives attackers complete access to data and the ability to alter or delete it.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle BI Publisher (part of Oracle Analytics) versions 8.2.0.0.0 and 12.2.1.4.0. Users running these versions are at risk.
Real-world impact
An attacker who exploits this vulnerability can hijack the BI Publisher service, read, modify, or delete sensitive business data, and disrupt reporting services for the organization.
Why this severity
The CVSS score of 9.8 reflects that the flaw is network‑accessible, requires no authentication, and compromises confidentiality, integrity, and availability of the entire application.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources