Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-61302: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. in Oracle Corpo

0
Critical
Published: 08/18/2026 (08/18/2026, 21:00:02 UTC)
Source: GCVE Database
Vendor/Project: Oracle Corporation
Product: Oracle Business Intelligence Enterprise Edition

Description

Oracle has released a Critical Security Patch Update (CSPU) in August 2026 addressing multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition and Oracle BI Publisher among many other Oracle products. This update includes 943 security patches targeting Oracle code and third-party components. Oracle strongly recommends applying these patches promptly to mitigate risks, as exploitation attempts have been reported against previously patched vulnerabilities. The affected products include various Oracle software versions across multiple product families, but specific affected versions for Oracle BI Enterprise Edition and BI Publisher are not explicitly detailed in the provided data.

CVSS v3.1

Score 8.2high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Affected software

Affected versions
OracleOracle BI Publishervers:unknown/*Oracle Business Intelligence Enterprise Edition

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 13:56:36 UTC

Technical Analysis

The August 2026 Oracle Critical Security Patch Update addresses multiple security vulnerabilities in Oracle Business Intelligence Enterprise Edition and Oracle BI Publisher, along with numerous other Oracle products. This CSPU provides targeted, high-priority fixes in a smaller, focused format to facilitate easier application with minimal disruption. The update contains 943 new security patches covering Oracle code and third-party components. Oracle advises customers to remain on actively supported versions and apply patches without delay due to ongoing reports of exploitation attempts against unpatched systems. The advisory references a broad range of affected Oracle products and versions but does not specify exact affected versions for the BI products in the provided data.

Potential Impact

The vulnerabilities addressed by this CSPU potentially expose affected Oracle products to security risks if unpatched. Exploitation attempts have been reported in the wild against previously patched vulnerabilities, indicating active threat activity targeting Oracle software. The impact includes potential compromise of confidentiality, integrity, or availability depending on the specific vulnerabilities fixed. However, no specific exploitation details or CVSS scores are provided in the data. The broad scope of the update underscores the criticality of applying these patches to maintain security posture.

Mitigation Recommendations

Oracle has released official patches as part of the August 2026 Critical Security Patch Update that address these vulnerabilities. Customers should promptly apply the provided patches to affected Oracle products and remain on actively supported versions. Oracle manages remediation for these on-premises products through patch releases; no cloud service remediation is indicated. Patch status is confirmed as official-fix. There is no indication that no action is required or that the issues are already mitigated without patching. Users should consult the Oracle advisory at https://www.oracle.com/security-alerts/cspuaug2026.html for detailed patch availability and installation instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Nationaal Cyber Security Centrum
Advisory Id
NCSC-2026-0313
Cve Count
16
Additional Cves
["CVE-2026-61305","CVE-2026-71055","CVE-2026-71056","CVE-2026-71057","CVE-2026-71058","CVE-2026-71059","CVE-2026-71061","CVE-2026-71094","CVE-2026-71095","CVE-2026-71096","CVE-2026-71097","CVE-2026-71098","CVE-2026-71099","CVE-2026-71107","CVE-2026-71122"]
Cvss Version
null

Threat ID: 6a85b4a3acd9273b49250766

Added to database: 08/19/2026, 13:50:27 UTC

Last enriched: 08/19/2026, 13:56:36 UTC

Last updated: 08/19/2026, 15:51:59 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses