Summary
CVE-2026-62633 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). The flaw allows an unauthenticated attacker with network access via HTTP to compromise the product and achieve complete takeover of confidentiality, integrity, and availability. Oracle rates it CRITICAL with a CVSS v3.1 base score of 9.8.
Technical details
- Root cause lies in the Security and Authentication component of Oracle Reports Developer.
- Oracle describes the issue as "easily exploitable" with no special conditions required to trigger it.
- Attack vector is network-based over HTTP; no authentication and no user interaction are required to exploit the flaw.
- Successful exploitation results in complete compromise of the underlying system, impacting confidentiality, integrity, and availability.
Affected software
- Oracle Reports Developer version 14.1.2.0.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.8 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Security Patch Update, which addresses CVE-2026-62633 for Oracle Reports Developer 14.1.2.0.0. Apply the update from Oracle as soon as possible.
- If immediate patching is not possible, restrict network access to Oracle Reports Developer (e.g., the Reports Server servlet) to trusted internal networks only, and monitor for anomalous HTTP requests to the Reports Developer endpoints until the patch can be applied.

