Summary
CVE-2026-62625 is a high-severity vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via SOAP to compromise the product, resulting in unauthorized access to (and potential modification of) accessible data as well as a partial denial of service. The flaw carries a CVSS v3.1 base score of 8.6 (High) and was disclosed in Oracle’s August 2026 Critical Patch Update.
Technical details
- Root cause: a weakness in the Security and Authentication component of Oracle Reports Developer that fails to properly restrict access to functionality exposed over SOAP.
- Trigger conditions: no authentication or user interaction is required; the attack complexity is rated low.
- Attack vector: network-based exploitation over the SOAP interface exposed by Oracle Reports Developer.
- Impact: unauthorized access to critical data (confidentiality: high), unauthorized update/insert/delete of some accessible data (integrity: low), and the ability to cause a partial denial of service (availability: low).
Affected software
- Oracle Reports Developer version 12.2.1.19.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Mitigation and recommended actions
- Immediate: apply the fix provided in Oracle’s August 2026 Critical Patch Update for Oracle Reports Developer 12.2.1.19.0.
- If patching cannot be performed immediately: restrict network access to the Oracle Reports Developer SOAP endpoint (e.g., via firewall rules, network segmentation, or reverse-proxy access controls) to trusted hosts only, and monitor for unusual SOAP requests to Reports services until the patch is applied.

