Summary
CVE-2026-62617 is a critical vulnerability in Oracle Reports Developer, a component of Oracle Fusion Middleware. It resides in the product’s Security and Authentication component and allows an unauthenticated, remote attacker to fully compromise the affected system over the network via UDP. Oracle rates the flaw CRITICAL with a CVSS 3.1 base score of 9.8.
Technical details
- Root cause: A flaw in the Security and Authentication component of Oracle Reports Developer.
- Attack vector: Network-based, reachable via UDP, requiring no authentication and no user interaction.
- Trigger conditions: Oracle describes the flaw as "easily exploitable," implying low attack complexity and no special access prerequisites.
- Impact: Successful exploitation can result in complete takeover of Oracle Reports Developer, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle Reports Developer, version 12.2.1.19.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Patch Update (CSPU) Advisory for the affected 12.2.1.19.0 release of Oracle Reports Developer.
- If patching cannot be applied immediately: Restrict or block UDP network access to Oracle Reports Developer services from untrusted networks, and limit exposure of the affected component to only trusted internal hosts until the patch can be deployed.

