Summary
CVE-2026-70668 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access to compromise the product via SOAP, resulting in unauthorized creation, deletion, or modification of data as well as unauthorized read access to all data accessible to the application. Oracle rates this issue 9.1 (Critical) on the CVSS v3.1 scale.
Technical details
- Root cause: A flaw in the Security and Authentication component of Oracle Reports Developer.
- Trigger conditions: The vulnerability is reachable over the network via the product’s SOAP interface, requires no authentication, and needs no user interaction.
- Attack vector: Network (AV:N), with low attack complexity (AC:L) and no privileges required (PR:N).
- Impact: Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, and unauthorized access to all data accessible to Oracle Reports Developer (high confidentiality and integrity impact; no availability impact).
Affected software
- Oracle Reports Developer 14.1.2.0.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Patch Update (CSPU) for Oracle Reports Developer version 14.1.2.0.0. Oracle states security patches must be applied promptly, as this vulnerability may be remotely exploitable without authentication.
- If patching cannot be applied immediately: Restrict network access to the Oracle Reports Developer SOAP interface (e.g., via firewall rules or network segmentation) to trusted hosts only, and monitor exposed Oracle Reports/Fusion Middleware endpoints for SOAP requests until the patch is deployed.

