NCSC-2026-0259 [1.00] [M/H] Vulnerabilities fixed in Oracle Analytics
Oracle has fixed multiple vulnerabilities in Oracle BI Publisher (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0) and Oracle Business Intelligence Enterprise Edition (versions 8.2.0.0.0 and 26.01.0.0.0). The vulnerabilities in Oracle BI Publisher and Oracle Business Intelligence Enterprise Edition allow unauthenticated attackers to achieve full system compromise via HTTP requests, bypass authentication, execute arbitrary code, perform denial of service attacks, and conduct unauthorized read, update, insert, or delete operations on underlying data. Additionally, low-privileged attackers can bypass authentication controls via the Web Service API, leading to unauthorized access to sensitive data, modification or deletion of critical information, and partial denial of service conditions.
CSIRTS triage
- What
- The vulnerabilities allow unauthenticated attackers to achieve full system compromise.
- Who is affected
- Users of Oracle BI Publisher and Oracle Business Intelligence Enterprise Edition.
- Urgency
- Remediation is urgent due to the potential for full system compromise.
- Action
- Update to the latest versions of Oracle BI Publisher and Oracle Business Intelligence Enterprise Edition.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Analytics
Get an email when a new Analytics advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0259
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-344800.86% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all scored CVEs.
- Low exploitation riskCVE-2026-398920.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all scored CVEs.
- Low exploitation riskCVE-2026-601730.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all scored CVEs.
- Low exploitation riskCVE-2026-606710.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-606730.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all scored CVEs.
- Low exploitation riskCVE-2026-606740.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-607190.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-34480 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-39892 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60173 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60671 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60673 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60674 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60719 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] Apache log4j: Multiple vulnerabilities allow file manipulationcert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle Weblogic (July 23, 2026)cert-fr-avis
- unknownNCSC-2026-0256 [1.00] [M/H] Vulnerabilities fixed in Oracle Communicationsncsc-nl
- criticalCVE-2026-60719: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service A…nvd
- highCVE-2026-60674: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- mediumCVE-2026-60673: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services)…nvd
- highCVE-2026-60671: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- criticalCVE-2026-60173: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform S…nvd
- unknownMultiple vulnerabilities in IBM products (July 10, 2026)cert-fr-avis
- high[NEW] [high] IBM Operational Decision Manager: Multiple vulnerabilitiescert-bund
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30