Summary
CVE-2026-62628 is a high-severity vulnerability in the Security and Authentication component of Oracle Reports Developer, a component of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via TCP to obtain unauthorized access to critical data, or complete access to all data accessible to Oracle Reports Developer. Oracle rates the issue 8.6 (High) and disclosed it in the August 2026 Critical Patch Update.
Technical details
- Root cause: a flaw in the Security and Authentication component of Oracle Reports Developer that fails to properly restrict access to data handled by the product.
- Trigger conditions: exploitable over the network via TCP; Oracle describes it as "easily exploitable."
- Attack vector: Network (AV:N), Low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: results in unauthorized access to critical data, or complete access to all data accessible to Oracle Reports Developer; the CVSS Scope is "Changed" (S:C), indicating impact can extend beyond the vulnerable component to other products.
- No integrity or availability impact is reported (I:N, A:N) — the impact is confined to confidentiality (C:H).
Affected software
- Oracle Reports Developer, version 12.2.1.19.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle August 2026 Critical Patch Update fix for Oracle Reports Developer version 12.2.1.19.0. Oracle states security patches must be applied to remain covered by Oracle Support, and patches are not available individually outside the associated Critical Patch Update.
- If a patch cannot be applied immediately: restrict network access (e.g., via firewall rules or network segmentation) to the Oracle Reports Developer service so only trusted hosts can reach it over TCP, since the vulnerability requires network access and no authentication or user interaction.
- Continue to monitor Oracle’s security alert for this Critical Patch Update for any updated guidance or supplemental information.

