CVE-2026-60173 is a critical, unauthenticated remote takeover vulnerability in Oracle BI Publisher, rated CVSS 9.8, disclosed in Oracle's July 2026 Critical Patch Update.
What Is It
CVE-2026-60173 is a vulnerability in the Oracle BI Publisher product of Oracle Analytics, specifically in the BI Platform Security component. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. A successful attack can result in complete takeover of the affected BI Publisher instance. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required.
Why It Matters
This vulnerability combines the worst attributes for defenders: it is reachable over the network, requires no authentication, needs no user interaction, and yields full compromise. The CVSS breakdown shows high impact across all three security properties, confidentiality, integrity, and availability, meaning a successful attacker can read data, alter it, and disrupt service. With an exploitability subscore of 3.9 (the maximum), any internet-exposed or otherwise reachable BI Publisher instance running an affected version is at serious risk.
What's Vulnerable
The supported versions affected are Oracle BI Publisher 8.2.0.0.0 and 12.2.1.4.0, per Oracle Corporation's advisory. The vulnerable component is BI Platform Security within Oracle Analytics.
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update (cpujul2026). Organizations running the affected versions should apply the fixes from that Critical Patch Update as the required remediation. Note: the supplied source material contains no CISA KEV entry for this CVE, so active exploitation is not confirmed by KEV at this time.
Sources
- NVD, CVE-2026-60173: https://nvd.nist.gov/vuln/detail/CVE-2026-60173
- Oracle Critical Patch Update Advisory (July 2026): https://www.oracle.com/security-alerts/cpujul2026.html