CVE-2026-60719
A critical flaw in Oracle BI Publisher’s Web Service API lets attackers with network access create, delete, or modify data and potentially cause a partial denial of service. The vulnerability can also expose all data accessible through the product. It is highly exploitable and can be triggered over HTTP.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle BI Publisher (Oracle Analytics) versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Users running these versions are at risk.
Real-world impact
An attacker could add, delete, or change data stored in Oracle BI Publisher, steal sensitive information, or disrupt service for users. The impact could extend to other Oracle products that rely on BI Publisher.
Why this severity
The CVSS score of 9.9 reflects that the flaw is network‑based, requires only low privileges, and can lead to complete confidentiality and integrity loss while also allowing a partial denial of service. The high impact on data and the ease of exploitation drive the critical rating.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoAdvisory updatedThe NVD record was last revised.