
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71059 is a critical remote code execution vulnerability in the Oracle BI Publisher product of Oracle Analytics, specifically affecting the Web Service API component. It affects versions 8.2.0.0.0 and 26.1.0.0.0. The vulnerability was disclosed and patched on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.9 (Critical), reflecting its ease of exploitation, network accessibility, and scope change impact (Oracle Advisory).
The vulnerability resides in the Web Service API component of Oracle BI Publisher and is exploitable via SOAP over the network. A low-privileged attacker with network access can exploit this flaw without any user interaction, making it "easily exploitable" per Oracle's classification. The scope change (S:C in the CVSS vector) indicates that a successful attack can extend beyond Oracle BI Publisher itself to significantly impact additional Oracle Analytics products. No specific CWE classification has been assigned by NVD at this time, and no public technical write-ups or proof-of-concept code have been identified (Oracle Advisory).
Successful exploitation can result in complete takeover of Oracle BI Publisher, with full compromise of confidentiality, integrity, and availability. An attacker can execute arbitrary code, modify data and configurations, and disrupt service availability. Due to the scope change, the impact extends beyond BI Publisher to additional Oracle Analytics products, increasing the risk of lateral movement within an Oracle Analytics deployment (Oracle Advisory).
As of the disclosure date (August 18, 2026), there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation. No threat actor attribution has been reported. The EPSS score is 0.0, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. However, the low attack complexity and minimal privilege requirements make this a high-priority target for future exploitation (Oracle Advisory).
Oracle has released a patch for CVE-2026-71059 as part of the August 2026 Critical Security Patch Update (CSPU), released on August 18, 2026. Affected versions are 8.2.0.0.0 and 26.1.0.0.0; administrators should apply the available patch immediately. As a temporary workaround, Oracle recommends restricting network access to the SOAP Web Service API to only trusted internal systems and implementing network segmentation to limit exposure of Oracle BI Publisher. Oracle strongly advises against relying on workarounds as a long-term solution (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."