Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Thu, 20 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle BI Publisher Web Service API Remote Takeover via Low-Privilege HTTP Access |
Thu, 20 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle BI Publisher Web Service API Unauthorized Access Leading to Application Takeover |
Wed, 19 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle BI Publisher Web Service API Unauthorized Access Leading to Application Takeover |
Wed, 19 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle BI Publisher Web Service API Remote Code Execution Vulnerability | |
| Weaknesses | CWE-285 CWE-287 |
Wed, 19 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle BI Publisher Web Service API Remote Code Execution Vulnerability | |
| Weaknesses | CWE-285 CWE-287 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle bi Publisher |
|
| CPEs | cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle bi Publisher |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:03:17.397Z
Updated: 2026-08-19T16:04:23.407Z
Reserved: 2026-08-04T22:06:34.614Z
Link: CVE-2026-71058
Updated: 2026-08-19T15:47:46.479Z
Status : Analyzed
Published: 2026-08-18T21:18:05.630
Modified: 2026-08-24T15:54:53.723
Link: CVE-2026-71058
No data.