NCSC-2026-0313 [1.00] [M/H] Vulnerabilities resolved in Oracle Business Intelligence Enterprise Edition and Oracle BI Publisher
Oracle has resolved multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition and Oracle BI Publisher. The vulnerabilities are present in different versions of Oracle Business Intelligence Enterprise Edition (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0) and Oracle BI Publisher (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0). Attackers with low privileges and network access via HTTP or SOAP can thereby obtain unauthorized access to sensitive data, bypass authentication controls, escalate privileges, modify or delete critical data, and in some cases gain complete control over the system. Some vulnerabilities can also lead to partial denial-of-service conditions. The vulnerabilities are present in components such as BI Search and the BI Publisher Web Service API. The CVSS 3.1 base scores range from 7.0 to 9.9, indicating impact on confidentiality, integrity and availability of the systems. Some attacks require user interaction or higher privileges, while others can also be exploited by unauthenticated attackers.
CSIRTS triage
- What
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition and BI Publisher allow low-privileged attackers to bypass authentication, escalate privileges, access sensitive data, and gain complete system control.
- Who is affected
- Deployments of Oracle Business Intelligence Enterprise Edition and BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
- Urgency
- High; attackers with low privileges and network access can exploit these via HTTP or SOAP to achieve full system compromise with CVSS scores up to 9.9.
- Action
- Apply Oracle security patches for Business Intelligence Enterprise Edition and BI Publisher to supported patch versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Business Intelligence Enterprise Edition and BI Publisher
Get an email when a new Business Intelligence Enterprise Edition and BI Publisher advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0313
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-613020.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-613050.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710550.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710560.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710570.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710580.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710590.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710610.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710940.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-710950.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-61302 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61305 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71055 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71056 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71057 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71058 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71059 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71061 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71094 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71095 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71096 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71097 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71098 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71099 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71107 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71122 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-71122: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- highCVE-2026-71107: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- highCVE-2026-71099: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- highCVE-2026-71098: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- highCVE-2026-71097: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- highCVE-2026-71096: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- highCVE-2026-71095: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- highCVE-2026-71094: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- highCVE-2026-71061: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analyti…nvd
- criticalCVE-2026-71059: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service A…nvd
- highCVE-2026-71058: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service A…nvd
- highCVE-2026-71057: Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform S…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0316 [1.00] [M/H] Vulnerabilities resolved in Oracle PeopleSoft Enterprise2026-08-19
- unknownNCSC-2026-0315 [1.00] [M/H] Vulnerabilities resolved in Oracle MySQL2026-08-19
- unknownNCSC-2026-0314 [1.00] [M/H] Vulnerabilities resolved in Oracle Java SE2026-08-19
- unknownNCSC-2026-0312 [1.00] [M/H] Vulnerabilities resolved in Oracle Financial Services2026-08-19
- unknownNCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Manager2026-08-19