PatchSiren cyber security CVE debrief
CVE-2026-60673 Oracle Corporation CVE debrief
The CVE-2026-60673 vulnerability affects Oracle BI Publisher's XML Services component, allowing low-privileged attackers with network access via HTTP to compromise the system and access critical data. This vulnerability has a CVSS score of 6.5, with Confidentiality impacts. The affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Organizations should prioritize patching to prevent low-privileged attackers from accessing critical data. The CVE record was published on 2026-07-21T22:18:08.213Z and has not been modified since then. The vulnerability is easily exploitable and allows unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data.
- Vendor
- Oracle Corporation
- Product
- Oracle BI Publisher
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-06
Who should care
Organizations using Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 should prioritize patching to prevent low-privileged attackers from accessing critical data. Security teams and operators should review the affected scope, severity, and vendor guidance to validate affected deployments and assign an owner for follow-up. Vulnerability management and platform teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Monitoring and detection teams should review compensating controls for exposed systems while remediation is scheduled and verified. Asset inventory teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Rollback and change window teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Source tracking teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Monitoring should be implemented to detect potential unauthorized access attempts. Asset inventory should be updated to reflect affected deployments. Rollback and change windows should be planned for remediation. Source tracking should be implemented to monitor for potential attacks. Security teams should review and update their security policies and procedures to address this vulnerability. Vulnerability management teams should prioritize patching for affected versions. Operators should review and update their systems to prevent low-privileged attackers from accessing critical data. Platform teams should review and update their platforms to prevent exploitation of this vulnerability. Compensating controls should be implemented to detect and prevent potential attacks. Monitoring and detection should be implemented to detect potential unauthorized access attempts. Asset inventory should be updated to reflect affected deployments. Rollback and change windows should be planned for remediation. Source tracking should be implemented to monitor for potential
Technical summary
The CVE-2026-60673 vulnerability affects Oracle BI Publisher's XML Services component, allowing low-privileged attackers with network access via HTTP to compromise the system and access critical data. The CVSS score is 6.5, with Confidentiality impacts. Affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability is easily exploitable and allows unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data.
Defensive priority
Oracle BI Publisher vulnerability allows low-privileged attackers to access critical data; prioritize patching for affected versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
Recommended defensive actions
- Apply patches for Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.
- Restrict network access to Oracle BI Publisher for low-privileged users.
- Monitor Oracle BI Publisher for unauthorized access attempts.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE-2026-60673 record indicates a vulnerability in Oracle BI Publisher's XML Services component, with a CVSS score of 6.5 and Confidentiality impacts. Affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. The vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle BI Publisher, potentially leading to unauthorized access to critical data.
Official resources
-
CVE-2026-60673 CVE record
CVE.org
-
CVE-2026-60673 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:08.213Z and has not been modified since then.