Summary
CVE-2026-70673 is a critical, remotely exploitable vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). It allows an unauthenticated attacker with network access via HTTP to compromise the product, gaining unauthorized access to critical or complete Reports Developer data along with limited unauthorized data modification. Oracle disclosed the issue in its August 2026 Critical Security Patch Update, and it carries a CVSS v3.1 base score of 9.3 (Critical).
Technical details
- Root cause lies in the Security and Authentication component of Oracle Reports Developer, allowing an authentication-related bypass.
- No privileges and no user interaction are required to exploit the flaw.
- Attack vector is network-based over HTTP, making internet-exposed Reports Developer/Reports Server instances directly reachable.
- Exploitation has a "Scope: Changed" designation, meaning impact can extend beyond Oracle Reports Developer to other components it interacts with.
- Impact is high confidentiality loss (unauthorized access to critical or all accessible data) and low integrity loss (unauthorized modification/deletion of some data); availability is not affected.
Affected software
- Oracle Reports Developer version 14.1.2.0.0 (Oracle Fusion Middleware)
Severity
- CVSS v3.1 Base Score: 9.3 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle August 2026 Critical Security Patch Update fixes for Oracle Reports Developer 14.1.2.0.0.
- If patching cannot be applied immediately: restrict network access to Reports Developer/Reports Server endpoints (e.g.,
rwservlet) from untrusted networks, place instances behind authenticated reverse proxies or VPN access, and monitor for anomalous unauthenticated requests to Reports Developer interfaces until the patch is deployed.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
href="/reports/rwservlet"

