Summary
CVE-2026-62609 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. It allows an unauthenticated, remote attacker with network access via TCP to fully compromise the affected system, with no user interaction or special privileges required. Oracle rates this issue CRITICAL with a CVSS v3.1 base score of 9.8.
Technical details
- Root cause lies in the Security and Authentication component of Oracle Reports Developer.
- Exploitation requires only network access over TCP to the affected service; Oracle describes it as "easily exploitable."
- No authentication, privileges, or user interaction are required to exploit the flaw.
- Successful exploitation results in complete takeover of Oracle Reports Developer, impacting confidentiality, integrity, and availability.
Affected software
- Oracle Reports Developer version 12.2.1.19.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the patch for Oracle Reports Developer 12.2.1.19.0 released in Oracle’s August 2026 Critical Security Patch Update (CSPU).
- If patching cannot be applied immediately, restrict network access to Oracle Reports Developer services (e.g., limit exposure of the
rwservletendpoint) to trusted internal networks only, and monitor for unusual authentication or servlet activity until the patch is deployed.

