Summary
CVE-2026-62629 is a critical vulnerability in Oracle Reports Developer, part of Oracle Fusion Middleware, affecting the product’s Security and Authentication component. It allows an unauthenticated, remote attacker to access the system over HTTP and perform unauthorized creation, deletion, or modification of critical data, as well as trigger denial-of-service conditions. Oracle rates the flaw 9.4 (Critical) on the CVSS v3.1 scale.
Technical details
- Root cause lies in the Security and Authentication component of Oracle Reports Developer.
- The flaw is described by Oracle as "easily exploitable," requiring no authentication and no user interaction.
- Attack vector is network-based over HTTP, meaning any internet-exposed Reports Developer instance is reachable without prior access or credentials.
- Successful exploitation permits unauthorized creation, deletion, or modification of critical data (integrity impact) and can cause the application to hang or crash (availability impact), with limited exposure of data (confidentiality impact).
Affected software
- Oracle Reports Developer version 14.1.2.0.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.4 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update released in the August 2026 Critical Patch Update Advisory, which addresses this vulnerability for Oracle Reports Developer 14.1.2.0.0.
- If patching cannot be applied immediately: Restrict network access to Reports Developer/Reports Server endpoints (e.g.,
rwservletand related HTTP interfaces) to trusted internal networks only, and place the service behind a web application firewall or reverse proxy that limits exposure to the public internet until the patch can be applied. - Review Oracle’s official advisory for any additional configuration-specific guidance before and after patching.

