Summary
CVE-2026-62640 is a critical authentication bypass vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware), version 14.1.2.0.0. The flaw allows an unauthenticated remote attacker with network access via the IIOP protocol to fully compromise the affected system. Oracle rates the issue 9.8 (CRITICAL) on the CVSS v3.1 scale, disclosed as part of Oracle’s August 2026 Critical Security Patch Update.
Technical details
- Root cause: a flaw in the Security and Authentication component of Oracle Reports Developer that permits authentication to be bypassed.
- Trigger conditions: the vulnerability is exploitable over the network via the IIOP (Internet Inter-ORB Protocol) interface exposed by the affected component; no credentials or user interaction are required.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: successful exploitation results in complete compromise of confidentiality, integrity, and availability of Oracle Reports Developer (C:H/I:H/A:H), i.e., full takeover of the affected system.
Affected software
- Oracle Reports Developer, version 14.1.2.0.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.8 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle patch for CVE-2026-62640 released in the August 2026 Critical Security Patch Update for Oracle Reports Developer 14.1.2.0.0.
- If patching cannot be applied immediately: restrict or disable network access to the IIOP interface used by Oracle Reports Developer, particularly from untrusted networks, and limit exposure of the Reports server to the internet until the patch is applied.

