PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61305 Oracle Corporation CVE debrief

The CVE-2026-61305 vulnerability is an easily exploitable issue in the Oracle BI Publisher product of Oracle Analytics, specifically in the BI Platform Security component. It allows low-privileged attackers with network access via HTTP to compromise Oracle BI Publisher, potentially leading to unauthorized creation, deletion, or modification access to critical data or all Oracle BI Publisher accessible data, as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. The CVSS 3.1 Base Score is 8.3, indicating high severity. Organizations should review and apply Oracle's security patches for affected BI Publisher versions, restrict network access to Oracle BI Publisher to only necessary personnel, and monitor Oracle BI Publisher logs for suspicious activity.

Vendor
Oracle Corporation
Product
Oracle BI Publisher
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-24
Advisory published
2026-08-18
Advisory updated
2026-08-24

Who should care

Organizations using Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 should prioritize patching this vulnerability to prevent potential data breaches and service disruptions. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and take necessary actions to protect their systems.

Technical summary

The CVE-2026-61305 vulnerability is an easily exploitable issue in the Oracle BI Publisher product of Oracle Analytics, specifically in the BI Platform Security component. It allows low-privileged attackers with network access via HTTP to compromise Oracle BI Publisher, potentially leading to unauthorized creation, deletion, or modification access to critical data or all Oracle BI Publisher accessible data, as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. The CVSS 3.1 Base Score is 8.3, indicating high severity.

Defensive priority

Oracle BI Publisher vulnerability allows low-privileged attackers to compromise data integrity and availability.

Recommended defensive actions

  • Review and apply Oracle's security patches for affected BI Publisher versions.
  • Restrict network access to Oracle BI Publisher to only necessary personnel.
  • Monitor Oracle BI Publisher logs for suspicious activity.
  • Implement compensating controls to detect and prevent potential attacks.
  • Verify inventory of Oracle BI Publisher instances and their versions.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE-2026-61305 vulnerability affects Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. It allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data access, modification, and partial denial of service. The vulnerability has a CVSS 3.1 Base Score of 8.3, indicating high severity. There is no information on known ransomware campaign use or exploitation. Defenders should verify inventory of Oracle BI Publisher instances and their versions, and implement compensating controls to detect and prevent potential attacks.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:59.123Z and has not been modified since then.