Summary
CVE-2026-62620 is a vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). It allows an unauthenticated, remote attacker over HTTP to gain unauthorized access to critical data, with the potential to obtain complete access to all data accessible to Oracle Reports Developer. Oracle rates the flaw HIGH severity (CVSS 3.1 base score 8.6).
Technical details
- Root cause: A flaw in the Security and Authentication component of Oracle Reports Developer.
- Trigger conditions: No authentication or user interaction is required; the flaw is easily exploitable.
- Attack vector: Network access via HTTP.
- Impact: Confidentiality impact is High (unauthorized or complete access to data accessible to Oracle Reports Developer); Integrity and Availability impacts are None. The CVSS Scope is Changed, meaning a successful attack may affect resources beyond the vulnerable component itself.
Affected software
- Oracle Reports Developer, version 12.2.1.19.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle in the August 2026 Critical Patch Update for the affected Oracle Reports Developer version 12.2.1.19.0.
- If patching cannot be applied immediately: Restrict or disable network/HTTP access to Oracle Reports Developer components (e.g., the Reports Server servlet) from untrusted networks until the patch is applied, since the vulnerability requires only network access via HTTP and no authentication.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body (HTML):
href="/reports/rwservlet

