
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61305 is an authorization bypass vulnerability in the BI Platform Security component of Oracle BI Publisher, part of the Oracle Analytics product family. It affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability was disclosed on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU) for August 2026. It carries a CVSS v3.1 base score of 8.3 (High) (Oracle Advisory, NVD).
The vulnerability resides in the BI Platform Security component of Oracle BI Publisher and is classified as an authorization bypass (CWE not formally assigned in NVD at time of publication). An attacker with low-level network privileges can exploit this flaw over HTTP without requiring user interaction, indicating insufficient access control enforcement within the security layer. The low attack complexity and absence of required user interaction make this vulnerability straightforward to exploit for any authenticated user with basic network access (Oracle Advisory, NVD).
Successful exploitation allows a low-privileged authenticated attacker to gain unauthorized read access to critical or all data accessible by Oracle BI Publisher, as well as unauthorized creation, deletion, or modification of critical data, and the ability to cause a partial denial of service. The combined high confidentiality and integrity impact means sensitive business intelligence reports, data sources, and configurations could be exposed or tampered with. Availability impact is rated low, indicating partial service disruption is possible but not a complete outage (Oracle Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Oracle Advisory). The EPSS score is reported at 0.0, reflecting a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.
Oracle has released a patch for CVE-2026-61305 as part of the August 2026 Critical Security Patch Update, and organizations should apply it immediately for all affected versions (8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0) (Oracle Advisory). As a temporary workaround prior to patching, restrict network access to Oracle BI Publisher to only trusted users and networks, and implement network segmentation to limit HTTP exposure. Oracle strongly advises against relying on network-level mitigations as a long-term solution, as they do not address the underlying vulnerability.
The vulnerability was noted by AUSCERT in their security bulletin ASB-2026.0186 and tracked by VulDB (entry 392545) shortly after Oracle's disclosure. No significant independent researcher commentary, vendor statements beyond Oracle's advisory, or notable social media discussion has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."