SYS::ONLINE
Wasteland.
Briefs1402
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60173 2026-07-21

Oracle BI Publisher Critical Takeover Flaw — CVE-2026-60173

"CVE-2026-60173 is a critical, unauthenticated remote takeover vulnerability in Oracle BI Publisher, rated CVSS 9.8, disclosed in Oracle's July 2026 Critical Patch Update."

CVE-2026-60173 is a critical, unauthenticated remote takeover vulnerability in Oracle BI Publisher, rated CVSS 9.8, disclosed in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60173 is a vulnerability in the Oracle BI Publisher product of Oracle Analytics, specifically in the BI Platform Security component. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. A successful attack can result in complete takeover of the affected BI Publisher instance. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required.

Why It Matters

This vulnerability combines the worst attributes for defenders: it is reachable over the network, requires no authentication, needs no user interaction, and yields full compromise. The CVSS breakdown shows high impact across all three security properties, confidentiality, integrity, and availability, meaning a successful attacker can read data, alter it, and disrupt service. With an exploitability subscore of 3.9 (the maximum), any internet-exposed or otherwise reachable BI Publisher instance running an affected version is at serious risk.

What's Vulnerable

The supported versions affected are Oracle BI Publisher 8.2.0.0.0 and 12.2.1.4.0, per Oracle Corporation's advisory. The vulnerable component is BI Platform Security within Oracle Analytics.

Patch Status

Oracle addressed this issue in its July 2026 Critical Patch Update (cpujul2026). Organizations running the affected versions should apply the fixes from that Critical Patch Update as the required remediation. Note: the supplied source material contains no CISA KEV entry for this CVE, so active exploitation is not confirmed by KEV at this time.

Sources