SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60719 2026-07-21

CVE-2026-60719: Critical Oracle BI Publisher Flaw Enables Full Data Compromise

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60719, a CVSS 9.9 vulnerability in Oracle BI Publisher's Web Service API that lets a low-privileged network attacker seize control of critical data."

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60719, a CVSS 9.9 vulnerability in Oracle BI Publisher's Web Service API that lets a low-privileged network attacker seize control of critical data.

What Is It

CVE-2026-60719 is a critical vulnerability in the Web Service API component of Oracle BI Publisher, part of the Oracle Analytics family. Oracle describes it as easily exploitable, allowing a low-privileged attacker with network access over HTTP to compromise the product. The flaw carries a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L, no user interaction required and a changed scope, meaning exploitation can spill beyond BI Publisher into additional products.

Why It Matters

The scope change is the standout risk here: although the bug lives in BI Publisher, Oracle warns that successful attacks "may significantly impact additional products." Consequences include unauthorized creation, deletion, or modification of critical data, complete read access to all BI Publisher–accessible data, and a partial denial of service. With low attack complexity and only low privileges required, the barrier to exploitation is minimal; a dangerous combination for a data-reporting platform that often sits close to sensitive business information.

What's Vulnerable

The affected product is Oracle BI Publisher (Oracle Analytics), specifically the Web Service API component. Oracle lists the following supported versions as affected:

Patch Status

Oracle addressed CVE-2026-60719 in its July 2026 Critical Patch Update (cpujul2026). Administrators running affected versions should apply the fixes from that update. The supplied source material contains no CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the wild at this time.

Sources