PatchSiren cyber security CVE debrief
CVE-2026-61305 Oracle Corporation CVE debrief
The CVE-2026-61305 vulnerability is an easily exploitable issue in the Oracle BI Publisher product of Oracle Analytics, specifically in the BI Platform Security component. It allows low-privileged attackers with network access via HTTP to compromise Oracle BI Publisher, potentially leading to unauthorized creation, deletion, or modification access to critical data or all Oracle BI Publisher accessible data, as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. The CVSS 3.1 Base Score is 8.3, indicating high severity. Organizations should review and apply Oracle's security patches for affected BI Publisher versions, restrict network access to Oracle BI Publisher to only necessary personnel, and monitor Oracle BI Publisher logs for suspicious activity.
- Vendor
- Oracle Corporation
- Product
- Oracle BI Publisher
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-24
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-24
Who should care
Organizations using Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 should prioritize patching this vulnerability to prevent potential data breaches and service disruptions. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and take necessary actions to protect their systems.
Technical summary
The CVE-2026-61305 vulnerability is an easily exploitable issue in the Oracle BI Publisher product of Oracle Analytics, specifically in the BI Platform Security component. It allows low-privileged attackers with network access via HTTP to compromise Oracle BI Publisher, potentially leading to unauthorized creation, deletion, or modification access to critical data or all Oracle BI Publisher accessible data, as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. The CVSS 3.1 Base Score is 8.3, indicating high severity.
Defensive priority
Oracle BI Publisher vulnerability allows low-privileged attackers to compromise data integrity and availability.
Recommended defensive actions
- Review and apply Oracle's security patches for affected BI Publisher versions.
- Restrict network access to Oracle BI Publisher to only necessary personnel.
- Monitor Oracle BI Publisher logs for suspicious activity.
- Implement compensating controls to detect and prevent potential attacks.
- Verify inventory of Oracle BI Publisher instances and their versions.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE-2026-61305 vulnerability affects Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. It allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data access, modification, and partial denial of service. The vulnerability has a CVSS 3.1 Base Score of 8.3, indicating high severity. There is no information on known ransomware campaign use or exploitation. Defenders should verify inventory of Oracle BI Publisher instances and their versions, and implement compensating controls to detect and prevent potential attacks.
Official resources
-
CVE-2026-61305 CVE record
CVE.org
-
CVE-2026-61305 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:59.123Z and has not been modified since then.