CVE-2026-60719
Oracle Analytics Publisher vulnerability analysis and mitigation

Overview

CVE-2026-60719 is a critical authorization bypass vulnerability in the Oracle BI Publisher Web Service API component of Oracle Analytics. It affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026. It carries a CVSS v3.1 base score of 9.9 (Critical), reflecting its network-accessible, low-complexity, low-privilege attack vector with a scope change impacting additional products (Oracle CPU July 2026).

Technical details

The vulnerability is rooted in multiple weaknesses including Improper Input Validation (CWE-20), Improper Privilege Management (CWE-269), Improper Access Control (CWE-284), and Uncontrolled Resource Consumption (CWE-400). A low-privileged attacker with network access via HTTP can send crafted requests to the Web Service API endpoint, bypassing authorization controls to gain unauthorized access to data and perform privileged operations. No user interaction is required, and the attack complexity is low, making it easily exploitable. The scope change in the CVSS vector indicates that successful exploitation can affect components beyond Oracle BI Publisher itself (Oracle CPU July 2026).

Impact

Successful exploitation allows a low-privileged attacker to gain complete read access to all data accessible by Oracle BI Publisher, perform unauthorized creation, deletion, or modification of critical data, and cause a partial denial of service to the application. Due to the scope change, attacks may significantly impact additional products integrated with or dependent on Oracle BI Publisher. This combination of high confidentiality and integrity impact, along with partial availability impact, makes this vulnerability particularly severe in enterprise analytics environments where BI Publisher handles sensitive business data (Oracle CPU July 2026).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Oracle CPU July 2026). The EPSS score is approximately 0.0042 (0.42%), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and minimal privilege requirement (only a valid low-privileged account is needed) make it a high-priority target if a PoC becomes public.

Exploitation steps

  1. Reconnaissance: Identify Oracle BI Publisher instances exposed over HTTP/HTTPS using network scanning tools (e.g., Shodan, Censys) or internal asset inventories, targeting versions 8.2.0.0.0, 12.2.1.4.0, or 26.01.0.0.0.
  2. Obtain low-privileged credentials: Acquire any valid low-privileged account on the Oracle BI Publisher instance — this could be through phishing, credential stuffing, or use of default credentials.
  3. Authenticate to the Web Service API: Use the obtained credentials to authenticate to the Oracle BI Publisher Web Service API endpoint via HTTP.
  4. Send crafted API requests: Submit specially crafted requests to the Web Service API that exploit the improper access control and input validation flaws, bypassing authorization checks to access privileged operations or data.
  5. Exfiltrate or manipulate data: Leverage the unauthorized access to read all accessible BI Publisher data, modify or delete critical data, or trigger resource exhaustion to cause partial denial of service.
  6. Pivot to additional products: Exploit the scope change to potentially affect other Oracle products integrated with BI Publisher in the environment (Oracle CPU July 2026).

Indicators of compromise

  • Network: Unusual or high-volume HTTP/HTTPS requests to Oracle BI Publisher Web Service API endpoints from low-privileged user accounts; requests originating from unexpected IP addresses or geographic locations.
  • Logs: Oracle BI Publisher access logs showing low-privileged accounts performing administrative or bulk data access operations; repeated API calls to sensitive endpoints outside of normal business hours.
  • Application Behavior: Unexpected data modifications, deletions, or creation events within BI Publisher reports or data sources; alerts for partial service unavailability or resource exhaustion tied to the BI Publisher service.
  • Authentication: Multiple authentication events from a single low-privileged account accessing the Web Service API in rapid succession, potentially indicating automated exploitation attempts.

Mitigation and workarounds

Oracle released a patch for CVE-2026-60719 on July 21, 2026, as part of the July 2026 Critical Patch Update. Affected users should apply the patch immediately for versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 by following the Oracle Analytics patch availability documentation. As interim workarounds, restrict network access to the Oracle BI Publisher Web Service API to trusted users and networks only, implement network segmentation to limit exposure, and monitor access logs for suspicious activity from low-privileged accounts. Oracle strongly recommends against relying on network-level workarounds as a long-term solution (Oracle CPU July 2026).

Additional resources


SourceThis report was generated using AI

Related Oracle Analytics Publisher vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71059CRITICAL9.9
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoNoAug 18, 2026
CVE-2026-60719CRITICAL9.9
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesJul 21, 2026
CVE-2026-71058HIGH8.8
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesAug 18, 2026
CVE-2026-71057HIGH8.5
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesAug 18, 2026
CVE-2026-61305HIGH8.3
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management