CVE-2026-71058
Oracle Analytics Publisher vulnerability analysis and mitigation

Overview

CVE-2026-71058 is a high-severity vulnerability in the Web Service API component of Oracle BI Publisher, part of the Oracle Analytics product family. It affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability allows a low-privileged attacker with network access via HTTP to achieve full takeover of the affected Oracle BI Publisher instance. It was disclosed and patched on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 8.8 (High) (Oracle Advisory).

Technical details

The vulnerability resides in the Web Service API component of Oracle BI Publisher and is described as "easily exploitable," requiring only low privileges and network access via HTTP with no user interaction. No specific CWE classification has been assigned by NVD at the time of publication, and Oracle has not publicly disclosed the precise root cause or exploitation mechanism beyond the risk matrix entry. The attack vector is network-based (AV:N), with low attack complexity (AC:L), low privileges required (PR:L), no user interaction (UI:N), and an unchanged scope (S:U), resulting in high impacts across confidentiality, integrity, and availability (Oracle Advisory).

Impact

Successful exploitation of CVE-2026-71058 can result in complete takeover of the Oracle BI Publisher instance, with high impact to confidentiality, integrity, and availability. An attacker could read sensitive report data and credentials, modify system configurations or published reports, and disrupt service availability. Given BI Publisher's role in enterprise reporting and its potential access to backend data sources, exploitation could facilitate lateral movement into connected databases or enterprise systems (Oracle Advisory).

Exploitability

As of the disclosure date (August 18, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is reported at 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and minimal privilege requirement make it an attractive target if exploit details become public.

Mitigation and workarounds

Oracle has released a patch for CVE-2026-71058 as part of the August 2026 Critical Security Patch Update (CSPU), published on August 18, 2026. Affected organizations should apply the patch immediately for Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. As a temporary workaround prior to patching, Oracle recommends restricting network access to the Web Service API component via HTTP to authorized users only, and monitoring BI Publisher logs for suspicious API activity. Oracle strongly advises against relying on network-level controls as a long-term solution (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Analytics Publisher vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71059CRITICAL9.9
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoNoAug 18, 2026
CVE-2026-60719CRITICAL9.9
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesJul 21, 2026
CVE-2026-71058HIGH8.8
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesAug 18, 2026
CVE-2026-71057HIGH8.5
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesAug 18, 2026
CVE-2026-61305HIGH8.3
  • Oracle Analytics Publisher logoOracle Analytics Publisher
  • cpe:2.3:a:oracle:bi_publisher
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management