
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60719 is a critical authorization bypass vulnerability in the Oracle BI Publisher Web Service API component of Oracle Analytics. It affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026. It carries a CVSS v3.1 base score of 9.9 (Critical), reflecting its network-accessible, low-complexity, low-privilege attack vector with a scope change impacting additional products (Oracle CPU July 2026).
The vulnerability is rooted in multiple weaknesses including Improper Input Validation (CWE-20), Improper Privilege Management (CWE-269), Improper Access Control (CWE-284), and Uncontrolled Resource Consumption (CWE-400). A low-privileged attacker with network access via HTTP can send crafted requests to the Web Service API endpoint, bypassing authorization controls to gain unauthorized access to data and perform privileged operations. No user interaction is required, and the attack complexity is low, making it easily exploitable. The scope change in the CVSS vector indicates that successful exploitation can affect components beyond Oracle BI Publisher itself (Oracle CPU July 2026).
Successful exploitation allows a low-privileged attacker to gain complete read access to all data accessible by Oracle BI Publisher, perform unauthorized creation, deletion, or modification of critical data, and cause a partial denial of service to the application. Due to the scope change, attacks may significantly impact additional products integrated with or dependent on Oracle BI Publisher. This combination of high confidentiality and integrity impact, along with partial availability impact, makes this vulnerability particularly severe in enterprise analytics environments where BI Publisher handles sensitive business data (Oracle CPU July 2026).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Oracle CPU July 2026). The EPSS score is approximately 0.0042 (0.42%), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and minimal privilege requirement (only a valid low-privileged account is needed) make it a high-priority target if a PoC becomes public.
Oracle released a patch for CVE-2026-60719 on July 21, 2026, as part of the July 2026 Critical Patch Update. Affected users should apply the patch immediately for versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 by following the Oracle Analytics patch availability documentation. As interim workarounds, restrict network access to the Oracle BI Publisher Web Service API to trusted users and networks only, implement network segmentation to limit exposure, and monitor access logs for suspicious activity from low-privileged accounts. Oracle strongly recommends against relying on network-level workarounds as a long-term solution (Oracle CPU July 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."