
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60173 is a critical improper access control vulnerability (CWE-284) in the Oracle BI Publisher product of Oracle Analytics, specifically in the BI Platform Security component. It affects versions 8.2.0.0.0 and 12.2.1.4.0. The vulnerability allows an unauthenticated remote attacker with network access via HTTP to fully compromise Oracle BI Publisher, resulting in complete takeover of the application. It was disclosed on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update, and carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory).
The vulnerability is classified under CWE-284 (Improper Access Control) and resides in the BI Platform Security component of Oracle BI Publisher. An unauthenticated attacker can exploit this flaw remotely over HTTP with low attack complexity, requiring no user interaction or privileges — making it highly automatable. Oracle has not publicly disclosed the specific technical mechanism, but the vulnerability's characteristics (network-accessible, no authentication required, full impact) are consistent with an authentication bypass or unauthenticated remote code execution pathway in the BI Platform Security layer (Oracle Advisory).
Successful exploitation results in complete takeover of Oracle BI Publisher, with high impact to confidentiality, integrity, and availability. An attacker could read sensitive business intelligence data and reports, modify application data and configurations, and disrupt service availability. Given BI Publisher's role in enterprise reporting and its typical access to sensitive organizational data sources, exploitation could also facilitate lateral movement into connected data systems (Oracle Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Oracle Advisory). The vulnerability is rated as automatable by NVD SSVC analysis, meaning it can be exploited at scale without manual interaction. The EPSS score is approximately 0.486%, indicating a currently low but non-negligible probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.
Oracle has released patches for CVE-2026-60173 as part of the July 2026 Critical Patch Update, published on July 21, 2026. Affected versions are 8.2.0.0.0 and 12.2.1.4.0; organizations should apply the relevant patches immediately via the Oracle Analytics patch documentation. As a temporary workaround, Oracle recommends restricting network access to Oracle BI Publisher endpoints to authorized users and networks only, and blocking HTTP access from untrusted networks. Oracle strongly advises against relying on network-level controls as a long-term solution and emphasizes prompt patch application (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."