CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0313 [1.00] [M/H] Vulnerabilities resolved in Oracle Business Intelligence Enterprise Edition and Oracle BI Publisher

unknownCVE-2026-61302CVE-2026-61305CVE-2026-71055CVE-2026-71056CVE-2026-71057CVE-2026-71058
Oracle has resolved multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition and Oracle BI Publisher. The vulnerabilities are present in different versions of Oracle Business Intelligence Enterprise Edition (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0) and Oracle BI Publisher (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0). Attackers with low privileges and network access via HTTP or SOAP can thereby obtain unauthorized access to sensitive data, bypass authentication controls, escalate privileges, modify or delete critical data, and in some cases gain complete control over the system. Some vulnerabilities can also lead to partial denial-of-service conditions. The vulnerabilities are present in components such as BI Search and the BI Publisher Web Service API. The CVSS 3.1 base scores range from 7.0 to 9.9, indicating impact on confidentiality, integrity and availability of the systems. Some attacks require user interaction or higher privileges, while others can also be exploited by unauthenticated attackers.

CSIRTS triage

What
Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition and BI Publisher allow low-privileged attackers to bypass authentication, escalate privileges, access sensitive data, and gain complete system control.
Who is affected
Deployments of Oracle Business Intelligence Enterprise Edition and BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Urgency
High; attackers with low privileges and network access can exploit these via HTTP or SOAP to achieve full system compromise with CVSS scores up to 9.9.
Action
Apply Oracle security patches for Business Intelligence Enterprise Edition and BI Publisher to supported patch versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Business Intelligence Enterprise Edition and BI Publisher

Get an email when a new Business Intelligence Enterprise Edition and BI Publisher advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-19
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0313

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-61302coverage & exploitation statusNVD · CVE.org
CVE-2026-61305coverage & exploitation statusNVD · CVE.org
CVE-2026-71055coverage & exploitation statusNVD · CVE.org
CVE-2026-71056coverage & exploitation statusNVD · CVE.org
CVE-2026-71057coverage & exploitation statusNVD · CVE.org
CVE-2026-71058coverage & exploitation statusNVD · CVE.org
CVE-2026-71059coverage & exploitation statusNVD · CVE.org
CVE-2026-71061coverage & exploitation statusNVD · CVE.org
CVE-2026-71094coverage & exploitation statusNVD · CVE.org
CVE-2026-71095coverage & exploitation statusNVD · CVE.org
CVE-2026-71096coverage & exploitation statusNVD · CVE.org
CVE-2026-71097coverage & exploitation statusNVD · CVE.org
CVE-2026-71098coverage & exploitation statusNVD · CVE.org
CVE-2026-71099coverage & exploitation statusNVD · CVE.org
CVE-2026-71107coverage & exploitation statusNVD · CVE.org
CVE-2026-71122coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories