Summary
CVE-2026-62610 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via HTTP to compromise the product, resulting in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible to Oracle Reports Developer. Oracle rates this as easily exploitable with a CVSS 3.1 base score of 9.1 (Critical).
Technical details
- Root cause: a flaw in the Security and Authentication component of Oracle Reports Developer that fails to properly restrict access.
- Trigger conditions: no authentication or user interaction is required; the flaw is reachable over the network via HTTP.
- Attack vector: network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: high confidentiality impact and high integrity impact (unauthorized read/write/delete of data accessible to the application); no availability impact is stated.
Affected software
- Oracle Reports Developer, version 12.2.1.19.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: apply the fix provided in Oracle’s Critical Security Patch Update for August 2026 (cspuaug2026) for the affected Oracle Reports Developer 12.2.1.19.0 installation.
- If immediate patching is not possible: restrict network exposure of Oracle Reports Developer/Reports Server endpoints (e.g.,
rwservlet) to trusted networks only, and monitor for unauthorized access attempts until the patch can be applied. Oracle also notes that Oracle Reports is deprecated and recommends migrating to Analytics Publisher.

