Summary
CVE-2026-62638 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (Oracle Fusion Middleware). It allows an unauthenticated attacker with network access via HTTP to compromise the product, resulting in unauthorized creation, deletion, or modification of accessible data and complete denial of service through hangs or repeated crashes. Oracle rates the flaw as easily exploitable and CRITICAL, with a CVSS 3.1 base score of 9.1.
Technical details
- Root cause: A flaw in the Security and Authentication component of Oracle Reports Developer that permits unauthorized operations without valid credentials.
- Trigger conditions: The vulnerability is remotely exploitable over HTTP and does not require authentication or user interaction.
- Attack vector: Network-based (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High integrity impact (unauthorized data creation/deletion/modification) and high availability impact (denial of service via hangs or crashes); no confidentiality impact.
Affected software
- Oracle Reports Developer, version 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Security Patch Update (CSPU) released August 18, 2026, which addresses CVE-2026-62638 for Oracle Reports Developer 14.1.2.0.0.
- If patching cannot be applied immediately: Restrict network access to Oracle Reports Developer HTTP endpoints (e.g., the Reports Server servlet) to trusted internal networks only, and monitor for anomalous unauthenticated requests to Reports Developer components until the patch can be deployed.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
href="/reports/rwservlet

