CVE-2026-60173: Critical severity Oracle Oracle BI Publisher vulnerability
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60173?
CVE-2026-60173 is rated as critical with a CVSS score of 9.8.
How do I fix CVE-2026-60173?
To fix CVE-2026-60173, update Oracle BI Publisher to the latest patched version.
What impact does CVE-2026-60173 have?
CVE-2026-60173 allows an unauthenticated attacker with network access to compromise Oracle BI Publisher.
Which versions are affected by CVE-2026-60173?
The vulnerable versions impacted by CVE-2026-60173 are Oracle BI Publisher 8.2.0.0.0 and 12.2.1.4.0.
Is CVE-2026-60173 easy to exploit?
Yes, CVE-2026-60173 is considered easily exploitable with network access via HTTP.