CVE-2026-71122
Oracle has resolved multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition and Oracle BI Publisher. The vulnerabilities are present in different versions of Oracle Business Intelligence Enterprise Edition (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0) and Oracle BI Publisher (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0). Attackers with low privileges and network access via HTTP or SOAP can thereby obtain unauthorized access to sensitive data, bypass authentication controls, escalate privileges, modify or delete critical data, and in some cases gain complete control over the system. Some vulnerabilities can also lead to partial denial-of-service conditions. The vulnerabilities are present in components such as BI Search and the BI Publisher Web Service API. The CVSS 3.1 base scores range from 7.0 to 9.9, indicating impact on confidentiality, integrity and availability of the systems. Some attacks require user interaction or higher privileges, while others can also be exploited by unauthenticated attackers.
CSIRTS triage
- What
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition and BI Publisher allow low-privileged attackers to bypass authentication, escalate privileges, access sensitive data, and gain complete system control.
- Who is affected
- Deployments of Oracle Business Intelligence Enterprise Edition and BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
- Urgency
- High; attackers with low privileges and network access can exploit these via HTTP or SOAP to achieve full system compromise with CVSS scores up to 9.9.
- Action
- Apply Oracle security patches for Business Intelligence Enterprise Edition and BI Publisher to supported patch versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-71122
Get an email if CVE-2026-71122 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-71122)