Summary
CVE-2026-62632 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). It allows an unauthenticated, remote attacker with only network access via HTTP to fully compromise the application, achieving high impact to confidentiality, integrity, and availability. The flaw carries a CVSS v3.1 base score of 9.8 (Critical) and requires no authentication or user interaction to exploit.
Technical details
- Root cause: A flaw in the "Security and Authentication" component of Oracle Reports Developer that permits an attacker to bypass authentication controls.
- Trigger conditions: No authentication or user interaction is required; the attacker only needs network access to the affected service.
- Attack vector: Network (remote), delivered over the HTTP protocol used by Oracle Reports Developer/Reports Services.
- Impact: Successful exploitation results in complete compromise of the Oracle Reports Developer installation, with high impact to confidentiality, integrity, and availability (full system takeover).
Affected software
- Oracle Reports Developer version 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Reports Developer security patch released in Oracle’s August 2026 Critical Security Patch Update (CSPU); upgrade the affected 14.1.2.0.0 installation to the fixed patch level provided in that advisory.
- If immediate patching is not possible: Restrict network access to the Oracle Reports Developer/Reports Services HTTP endpoints (e.g., the
rwservletinterface) to trusted internal networks only, and monitor for anomalous unauthenticated requests to these services until the patch can be applied.

