CVE-2026-60673: Infoleak
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs network access to the Oracle BI Publisher XML Services interface over HTTP and a low-privileged account. No user interaction is required.
What is the potential impact of successful exploitation?
Successful exploitation can expose critical data or provide access to all data accessible through Oracle BI Publisher. The reported impact is confidentiality-only; integrity and availability impacts are not indicated.
Which versions are identified as affected?
The affected supported versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0.