Summary
CVE-2026-62614 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). It allows an unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer, with Oracle’s advisory noting successful exploitation can result in complete takeover of the product. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: A flaw in the Security and Authentication component of Oracle Reports Developer; Oracle has not disclosed further technical/root-cause detail beyond the component name.
- Trigger conditions: No authentication or user interaction is required; the vulnerability is remotely exploitable over HTTP.
- Attack vector: Network-based (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High impact to confidentiality, integrity, and availability — Oracle describes the outcome as complete takeover of Oracle Reports Developer.
Affected software
- Oracle Reports Developer, version 12.2.1.19.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Patch Update / Security Alert (cspuaug2026) for Oracle Reports Developer 12.2.1.19.0. Confirm patch application against Oracle’s published advisory for the exact patch identifier for your deployment.
- If patch cannot be applied immediately: Restrict network access to Oracle Reports Developer interfaces (e.g., via firewall/segmentation) so they are not reachable from untrusted networks, and monitor for anomalous unauthenticated HTTP requests to the Reports Developer service until the patch can be deployed.
How IONIX identifies potentially affected assets
IONIX matches the following signal against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
href="/reports/rwservlet

