Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60673

CVE-2026-60673: Oracle BI Publisher Information Disclosure

CVE-2026-60673 is an information disclosure vulnerability in Oracle BI Publisher XML Services that allows unauthorized access to critical data. This post covers technical details, affected versions, impact, and mitigation.

Updated:

CVE-2026-60673 Overview

CVE-2026-60673 is an information disclosure vulnerability in Oracle BI Publisher, part of the Oracle Analytics product family. The flaw resides in the XML Services component and affects supported versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. A low-privileged attacker with network access over HTTP can exploit this issue without user interaction. Successful exploitation results in unauthorized access to critical data or complete access to all data reachable by Oracle BI Publisher. Oracle addressed the vulnerability in the July 2026 Critical Patch Update.

Critical Impact

Authenticated network attackers can retrieve confidential data processed by Oracle BI Publisher, exposing enterprise reporting content and any datasources bound to the reporting engine.

Affected Products

  • Oracle BI Publisher 8.2.0.0.0
  • Oracle BI Publisher 12.2.1.4.0
  • Oracle BI Publisher 26.01.0.0.0

Discovery Timeline

  • 2026-07-21 - CVE-2026-60673 published to the National Vulnerability Database
  • 2026-07-21 - Last updated in NVD database
  • July 2026 - Oracle releases fix as part of the Oracle Critical Patch Update

Technical Details for CVE-2026-60673

Vulnerability Analysis

The vulnerability is located in the XML Services component of Oracle BI Publisher. Oracle categorizes the impact as confidentiality-only, with no effect on integrity or availability. The issue is remotely exploitable over HTTP and requires only a low-privileged authenticated session. Because BI Publisher aggregates data from multiple back-end sources for reporting, unauthorized access can extend across datasets loaded into the publishing engine.

The EPSS score is 0.355% with a percentile of 28.04 as of 2026-07-23, indicating that in-the-wild exploitation activity has not yet been observed. No public exploit or proof-of-concept has been released.

Root Cause

Oracle has not published detailed root cause information beyond the affected component. Based on the advisory metadata, the flaw stems from improper access control or input handling within the XML Services layer that processes report and template requests. This class of issue in reporting engines commonly maps to XML External Entity (XXE) processing, insufficient authorization checks on XML endpoints, or path traversal via XML-referenced resources. Consult the Oracle Critical Patch Update for authoritative technical details.

Attack Vector

An attacker authenticates to BI Publisher with a low-privileged account. The attacker then sends crafted HTTP requests to the XML Services endpoint. The server processes the request under a privileged context and returns data the attacker is not authorized to view. No user interaction is required, and the scope remains unchanged, meaning the impact is bounded to the BI Publisher instance and the data it can reach.

Because the attack is network-based and requires only valid credentials, exposed BI Publisher instances with weak internal segmentation or shared user pools present the highest risk.

Detection Methods for CVE-2026-60673

Indicators of Compromise

  • Unexpected HTTP requests to BI Publisher XML Services endpoints originating from low-privileged accounts or unusual source IPs.
  • Large or repeated report exports and XML responses correlated with accounts that do not typically consume those reports.
  • Access to XML Services paths outside a user's normal reporting workflow, especially during off-hours.

Detection Strategies

  • Enable and review BI Publisher access, audit, and diagnostic logs for anomalous XML Services activity per user.
  • Correlate WebLogic or fronting reverse-proxy logs with BI Publisher authentication events to identify accounts issuing atypical HTTP patterns.
  • Baseline expected report and dataset access per role, then alert on deviations such as bulk enumeration of report IDs.

Monitoring Recommendations

  • Forward BI Publisher, WebLogic, and web tier logs into a centralized SIEM for retention and correlation.
  • Monitor authentication logs for low-privileged accounts producing high volumes of XML Services requests.
  • Track outbound data volumes from the BI Publisher host to detect potential bulk data exfiltration.

How to Mitigate CVE-2026-60673

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update to all affected BI Publisher deployments.
  • Inventory instances running versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 and prioritize internet-exposed servers.
  • Rotate credentials for BI Publisher accounts if suspicious XML Services access is identified in logs.
  • Restrict network access to BI Publisher management and XML Services endpoints to trusted administrative networks.

Patch Information

Oracle released fixes for CVE-2026-60673 in the July 2026 Critical Patch Update. Administrators should download and apply the appropriate patch bundle from My Oracle Support after validating the target version. Refer to the Oracle Critical Patch Update for full patch identifiers, prerequisites, and installation guidance.

Workarounds

  • Place BI Publisher behind a reverse proxy or WAF and restrict XML Services URIs to authenticated administrative sources until patched.
  • Enforce least privilege on BI Publisher accounts and remove unused local users to shrink the pool of accounts able to exploit the flaw.
  • Disable or firewall off external HTTP access to BI Publisher where business use cases do not require it.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.