External risk intelligence

Oracle BI Publisher Unauthenticated Network Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60173

Oracle BI Publisher is commonly deployed as a web-based reporting and analytics application. These platforms are frequently configured as internet-facing or externally reachable web services to allow authorized users to access reports and dashboards remotely, making network-accessible endpoints a common deployment pattern.

Oracle Bi Publisher

8.2.0.0.012.2.1.4.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle BI Publisher, a component of Oracle Analytics. This issue, if exploited, could allow an attacker to gain complete control over the BI Publisher system. The ease of exploitation and the potential for a full system takeover present a significant concern for organizations utilizing this technology for reporting and analytics.

  • Unauthenticated attackers can take over BI Publisher.
  • Protects critical reporting and analytics capabilities.
  • Confirm if Oracle BI Publisher is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access can exploit this vulnerability to compromise Oracle BI Publisher. By targeting the BI Platform Security component, an attacker can gain full control over the system.

  • Network access required.
  • Vulnerable BI Platform Security component.
  • Full system takeover possible.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise Oracle BI Publisher, leading to a complete takeover of the application. This could affect the confidentiality, integrity, and availability of the BI Publisher service.

  • Oracle BI Publisher system and data.
  • Via unauthenticated network access.
  • Complete takeover of the application.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle BI Publisher impacts Oracle Analytics. Given its web-based nature and common deployment as a remote access tool, platform or infrastructure teams are likely responsible for the affected components. The first critical step is to identify all instances of Oracle BI Publisher, confirm their network reachability and business criticality, and then assign ownership for remediation planning.

  • Platform/Infrastructure teams own resolution.
  • Verify network exposure and business impact.
  • Plan risk-based remediation activities.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle BI Publisher?

Oracle BI Publisher is a centralized reporting and analytics component within the Oracle Analytics suite. It is used by organizations to design, manage, and deliver high-volume reports and business documents to diverse destinations like email, printers, or web portals. Because it handles complex data integration, it often acts as a critical hub for business intelligence workflows.

How does CVE-2026-60173 impact BI Platform Security?

This vulnerability affects the BI Platform Security component of the software. It represents a flaw in how the system handles authentication and access requests. By bypassing these security controls, an unauthorized party could gain the same level of administrative control over the application as a legitimate user, potentially allowing them to view sensitive data or modify system configurations.

Does this vulnerability require special user privileges to trigger?

No. The vulnerability is unauthenticated, meaning an attacker does not need an account, a password, or any prior access to the system to initiate an attack. It is triggered through simple network requests over HTTP. It cannot be triggered by someone who lacks network connectivity to the BI Publisher service, such as a user restricted to a completely isolated local environment without web reachability.

How can I tell if my instance of Oracle BI Publisher is at risk?

According to Halo Surface Signal, Oracle BI Publisher is frequently deployed as a web-based service accessible over a network. If your installation is configured to be reachable from the internet or external segments to support remote report viewing, it faces a higher level of risk. You should review your network perimeter and service hosting configuration to determine if the BI Publisher endpoint is exposed.

What is the first step to address this issue?

The priority is to conduct a thorough inventory to locate all active Oracle BI Publisher instances within your environment. Once identified, verify their current version against the affected releases (8.2.0.0.0 and 12.2.1.4.0) and assess their network accessibility. Consult official Oracle security guidance to determine the appropriate update path or mitigation steps for your specific deployment.

References