CVE-2026-71059 – Oracle BI Publisher
CVSS 9.9
CRITICAL
Critical - Same Day Deployment
“A low-privileged authenticated attacker can reach a Critical compromise path through the BI Publisher web service API.”
Oracle addresses a Critical vulnerability in the Web Service API component of Oracle BI Publisher. CVE-2026-71059 is remotely exploitable over SOAP by a low-privileged authenticated attacker and can result in high impact to confidentiality, integrity, and availability. The CVSS score is 9.9, which is Critical severity.
Affected versions include Oracle BI Publisher 8.2.0.0.0 and 26.1.0.0.0. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.
Key Details
- Affected Product
- Oracle Bi Publisher
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-284
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.