Skip to content
feed: live
>_ 0dayNews
CVE Record
[ CRITICAL ] CVE-2025-61882

Oracle E-Business Suite BI Publisher Integration unauth RCE

A critical authentication-bypass and remote-code-execution flaw in the BI Publisher Integration component of Oracle E-Business Suite (versions 12.2.3–12.2.14). Exploited in the wild by Cl0p since August 2025; linked to the Estée Lauder HR-system breach disclosed July 20, 2026.

cat cve-2025-61882.json
Vendor
Oracle
Product
E-Business Suite — BI Publisher Integration (versions 12.2.3–12.2.14)
CVSS
9.8
EPSS (exploit probability)
N/A
Status
exploited-in-wild
Published

CVE-2025-61882 is an unauthenticated remote-code-execution flaw in the BI Publisher Integration component of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.14. Per NVD, a network attacker can bypass authentication and execute code in the context of the EBS process — CVSS 9.8. The Cl0p extortion crew has been exploiting the flaw in the wild since early August 2025, per BleepingComputer’s reporting on the Estée Lauder disclosure of 2026-07-20.

Why it matters

Oracle E-Business Suite carries the HR-of-record, payroll, and payments data for a large share of Fortune 500 and public-sector organizations. BI Publisher Integration is a reporting and document-generation surface with reach into the underlying EBS data model — a full compromise of that component is a full read of whatever the EBS instance holds.

Unauthenticated over the network means there is no credential requirement and no user interaction. Any Internet-reachable EBS instance in the affected version band that was unpatched during the Cl0p mass-exploitation window should be treated as breached, not “at risk.” The Estée Lauder timeline — access on 2025-08-09, discovery on 2026-06-19 — is the concrete example of what dwell looks like on this specific bug against this specific attacker.

What to do

Confirm the EBS build number against Oracle’s security-alert publications for CVE-2025-61882 and apply the vendor-supplied fix if the instance is in the 12.2.3–12.2.14 range and unpatched. Do not rely on patch-management dashboards alone — cross-check the running build. If the instance was exposed to the Internet during the exploitation window (August 2025 forward), pull BI Publisher access logs, search for unfamiliar service or admin accounts, and review outbound flows sized to match record-set extraction. For related coverage of the parallel EBS Payments/File Transmission RCE, see CVE-2026-46817.