CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-71059

criticalCVSS 9.9covered by 2 sourcesfirst seen 2026-08-18
Oracle has resolved multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition and Oracle BI Publisher. The vulnerabilities are present in different versions of Oracle Business Intelligence Enterprise Edition (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0) and Oracle BI Publisher (versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0). Attackers with low privileges and network access via HTTP or SOAP can thereby obtain unauthorized access to sensitive data, bypass authentication controls, escalate privileges, modify or delete critical data, and in some cases gain complete control over the system. Some vulnerabilities can also lead to partial denial-of-service conditions. The vulnerabilities are present in components such as BI Search and the BI Publisher Web Service API. The CVSS 3.1 base scores range from 7.0 to 9.9, indicating impact on confidentiality, integrity and availability of the systems. Some attacks require user interaction or higher privileges, while others can also be exploited by unauthenticated attackers.

CSIRTS triage

What
Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition and BI Publisher allow low-privileged attackers to bypass authentication, escalate privileges, access sensitive data, and gain complete system control.
Who is affected
Deployments of Oracle Business Intelligence Enterprise Edition and BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Urgency
High; attackers with low privileges and network access can exploit these via HTTP or SOAP to achieve full system compromise with CVSS scores up to 9.9.
Action
Apply Oracle security patches for Business Intelligence Enterprise Edition and BI Publisher to supported patch versions.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-71059

Get an email if CVE-2026-71059 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-71059

CVE.org record

Embed the live status

CVE-2026-71059 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-71059 status](https://www.csirts.com/badge/CVE-2026-71059)](https://www.csirts.com/cve/CVE-2026-71059)