
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71058 is a high-severity vulnerability in the Web Service API component of Oracle BI Publisher, part of the Oracle Analytics product family. It affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability allows a low-privileged attacker with network access via HTTP to achieve full takeover of the affected Oracle BI Publisher instance. It was disclosed and patched on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 8.8 (High) (Oracle Advisory).
The vulnerability resides in the Web Service API component of Oracle BI Publisher and is described as "easily exploitable," requiring only low privileges and network access via HTTP with no user interaction. No specific CWE classification has been assigned by NVD at the time of publication, and Oracle has not publicly disclosed the precise root cause or exploitation mechanism beyond the risk matrix entry. The attack vector is network-based (AV:N), with low attack complexity (AC:L), low privileges required (PR:L), no user interaction (UI:N), and an unchanged scope (S:U), resulting in high impacts across confidentiality, integrity, and availability (Oracle Advisory).
Successful exploitation of CVE-2026-71058 can result in complete takeover of the Oracle BI Publisher instance, with high impact to confidentiality, integrity, and availability. An attacker could read sensitive report data and credentials, modify system configurations or published reports, and disrupt service availability. Given BI Publisher's role in enterprise reporting and its potential access to backend data sources, exploitation could facilitate lateral movement into connected databases or enterprise systems (Oracle Advisory).
As of the disclosure date (August 18, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is reported at 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and minimal privilege requirement make it an attractive target if exploit details become public.
Oracle has released a patch for CVE-2026-71058 as part of the August 2026 Critical Security Patch Update (CSPU), published on August 18, 2026. Affected organizations should apply the patch immediately for Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. As a temporary workaround prior to patching, Oracle recommends restricting network access to the Web Service API component via HTTP to authorized users only, and monitoring BI Publisher logs for suspicious API activity. Oracle strongly advises against relying on network-level controls as a long-term solution (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."