Summary
CVE-2026-62635 is a critical, unauthenticated, network-exploitable vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). It is remotely exploitable over HTTP without credentials or user interaction, and Oracle rates it as easily exploitable, with successful exploitation resulting in complete compromise of the host’s confidentiality, integrity, and availability.
Technical details
- Root cause: Flaw in the Security and Authentication component of Oracle Reports Developer.
- Trigger conditions: Exploitable by sending crafted requests over HTTP; no authentication or user interaction is required.
- Attack vector: Network (AV:N), low attack complexity, no privileges required, no user interaction.
- Impact: Complete takeover of the Oracle Reports Developer host, with high impact to confidentiality, integrity, and availability; scope is unchanged.
Affected software
- Oracle Reports Developer, version 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update for August 2026, which addresses CVE-2026-62635 for Oracle Reports Developer 14.1.2.0.0. Oracle states patches are available for this CVE.
- If patching cannot be applied immediately: Restrict network access to the Oracle Reports Developer HTTP interface (e.g., the reports servlet) to trusted internal networks only, and monitor for unexpected inbound HTTP requests to Reports Developer endpoints until the patch is deployed.

