CVE-2026-71059 – Oracle BI Publisher

CVSS 9.9 CRITICAL Critical - Same Day Deployment

“A low-privileged authenticated attacker can reach a Critical compromise path through the BI Publisher web service API.”

Oracle addresses a Critical vulnerability in the Web Service API component of Oracle BI Publisher. CVE-2026-71059 is remotely exploitable over SOAP by a low-privileged authenticated attacker and can result in high impact to confidentiality, integrity, and availability. The CVSS score is 9.9, which is Critical severity.

Affected versions include Oracle BI Publisher 8.2.0.0.0 and 26.1.0.0.0. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.

Key Details

Affected Product
Oracle Bi Publisher
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-284
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.