CVE-2026-60173
Oracle Analytics Publisher vulnerability analysis and mitigation

Overview

CVE-2026-60173 is a critical improper access control vulnerability (CWE-284) in the Oracle BI Publisher product of Oracle Analytics, specifically in the BI Platform Security component. It affects versions 8.2.0.0.0 and 12.2.1.4.0. The vulnerability allows an unauthenticated remote attacker with network access via HTTP to fully compromise Oracle BI Publisher, resulting in complete takeover of the application. It was disclosed on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update, and carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory).

Technical details

The vulnerability is classified under CWE-284 (Improper Access Control) and resides in the BI Platform Security component of Oracle BI Publisher. An unauthenticated attacker can exploit this flaw remotely over HTTP with low attack complexity, requiring no user interaction or privileges — making it highly automatable. Oracle has not publicly disclosed the specific technical mechanism, but the vulnerability's characteristics (network-accessible, no authentication required, full impact) are consistent with an authentication bypass or unauthenticated remote code execution pathway in the BI Platform Security layer (Oracle Advisory).

Impact

Successful exploitation results in complete takeover of Oracle BI Publisher, with high impact to confidentiality, integrity, and availability. An attacker could read sensitive business intelligence data and reports, modify application data and configurations, and disrupt service availability. Given BI Publisher's role in enterprise reporting and its typical access to sensitive organizational data sources, exploitation could also facilitate lateral movement into connected data systems (Oracle Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Oracle Advisory). The vulnerability is rated as automatable by NVD SSVC analysis, meaning it can be exploited at scale without manual interaction. The EPSS score is approximately 0.486%, indicating a currently low but non-negligible probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.

Mitigation and workarounds

Oracle has released patches for CVE-2026-60173 as part of the July 2026 Critical Patch Update, published on July 21, 2026. Affected versions are 8.2.0.0.0 and 12.2.1.4.0; organizations should apply the relevant patches immediately via the Oracle Analytics patch documentation. As a temporary workaround, Oracle recommends restricting network access to Oracle BI Publisher endpoints to authorized users and networks only, and blocking HTTP access from untrusted networks. Oracle strongly advises against relying on network-level controls as a long-term solution and emphasizes prompt patch application (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Analytics Publisher vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71059CRITICAL9.9
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoNoAug 18, 2026
CVE-2026-60719CRITICAL9.9
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesJul 21, 2026
CVE-2026-71058HIGH8.8
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesAug 18, 2026
CVE-2026-71057HIGH8.5
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesAug 18, 2026
CVE-2026-61305HIGH8.3
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management