Summary
CVE-2026-62621 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. It allows an unauthenticated, remote attacker with network access to fully compromise the affected application, with high impact to confidentiality, integrity, and availability. Oracle disclosed the flaw in its August 2026 Critical Security Patch Update with a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: A flaw in the Security and Authentication component of Oracle Reports Developer.
- Trigger conditions: No authentication or user interaction is required to exploit the vulnerability.
- Attack vector: Exploitable remotely over the network (TCP), with low attack complexity and no privileges required.
- Impact: Successful exploitation can result in complete takeover of Oracle Reports Developer, with high impact to confidentiality, integrity, and availability of the affected system.
Affected software
- Oracle Reports Developer version 12.2.1.19.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.8 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix for Oracle Reports Developer issued in Oracle’s August 2026 Critical Security Patch Update. Organizations running Oracle Reports Developer 12.2.1.19.0 should update to the patched release identified in Oracle’s advisory as soon as possible.
- If immediate patching is not possible: Restrict network access to Oracle Reports Developer services (e.g., the Reports Servlet) to trusted internal networks only, and monitor for anomalous requests to Reports Developer endpoints until the patch can be applied.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
href="/reports/rwservlet"

