Summary
CVE-2026-62634 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via CORBA to fully compromise the affected system, and Oracle rates it as easily exploitable. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause lies in the Security and Authentication component of Oracle Reports Developer.
- Exploitation occurs over the network via the CORBA protocol.
- No authentication credentials and no user interaction are required to exploit the vulnerability.
- Attack complexity is low, meaning exploitation does not require special conditions.
- Successful exploitation results in complete compromise of confidentiality, integrity, and availability of the affected system.
Affected software
- Oracle Reports Developer version 14.1.2.0.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Patch Update (Critical Security Patch Update Advisory) for Oracle Reports Developer 14.1.2.0.0.
- If patching cannot be performed immediately, restrict network access to the CORBA interface/ports used by Oracle Reports Developer to trusted hosts only, using firewalls or network segmentation, until the patch can be applied.
- Review exposure of Oracle Reports Developer instances on the internet or untrusted networks and remove unnecessary external access.

