Oracle BI Enterprise 8.2.0.0.0/26.01.0.0.0 Unauthenticated HTTP Access High
CVE-2026-60674 Published on July 21, 2026
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Vulnerability Analysis
CVE-2026-60674 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and no impact on availability.
Weakness Types
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-60674 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2026-60674
stack.watch emails you whenever new vulnerabilities are published in Oracle Business Intelligence or Oracle. Just hit a watch button to start following.
Affected Versions
Oracle Corporation Oracle Business Intelligence Enterprise Edition:- Version 8.2.0.0.0 is affected.
- Version 26.01.0.0.0 is affected.