Summary
CVE-2026-62626 is a critical, unauthenticated remote code execution vulnerability in Oracle Reports Developer, a component of Oracle Fusion Middleware. It resides in the product’s Security and Authentication component and allows a network attacker to fully compromise the affected system without credentials or user interaction. Oracle rates this vulnerability CRITICAL with a CVSS v3.1 base score of 9.8.
Technical details
- Root cause: A flaw in the Security and Authentication component of Oracle Reports Developer.
- Trigger conditions: No authentication or user interaction is required to exploit the flaw.
- Attack vector: Network access via HTTP; Oracle describes the vulnerability as "easily exploitable."
- Impact: Successful exploitation can result in complete takeover of Oracle Reports Developer, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle Reports Developer, version 12.2.1.19.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Patch Update (CSPU) for Oracle Reports Developer 12.2.1.19.0. Oracle strongly recommends applying the update as soon as possible.
- If patching cannot be performed immediately: Restrict network access to Oracle Reports Developer services (e.g., limit exposure of the
rwservletinterface to trusted networks only) until the patch can be applied, since the vulnerability is remotely exploitable over HTTP without authentication.
How IONIX identifies potentially affected assets
IONIX matches the following signal against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
href="/reports/rwservlet

