Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized read access to a subset of Oracle Reports Developer accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H).
Published: 2026-08-18
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Reports Developer version 14.1.2.0.0 contains an easily exploitable vulnerability in the Security and Authentication component that allows an unauthenticated attacker to create, delete or modify data, read a subset of data, and cause the application to hang or crash. The flaw results in confidentiality, integrity, and availability impacts, with a CVSS 3.1 base score of 9.4.

Affected Systems

The affected product is Oracle Reports Developer 14.1.2.0.0 from Oracle Corporation. No other versions are listed as impacted.

Risk and Exploitability

The vulnerability can be triggered by network traffic sent over HTTP and does not require authentication or user interaction. With a CVSS score of 9.4 the severity is critical, and the EPSS score of < 1% indicates a low probability of exploitation; the issue is not yet listed in the CISA KEV catalog. Attackers can exploit it remotely and autonomously, but the likelihood of exploitation is low based on the EPSS score.

Generated by OpenCVE AI on August 26, 2026 at 22:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or update for Reports Developer 14.1.2.0.0 released by Oracle.
  • Restrict network access to the Reports Developer service to authorized IP ranges or VPNs to limit exposure.
  • Configure application‑level or firewall filtering to block anomalous HTTP requests that may trigger the crash or unauthorized data manipulation.
  • Enable detailed audit logging and monitor logs for unauthorized read or write attempts to detect potential exploitation.

Generated by OpenCVE AI on August 26, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allowing Data Manipulation and Denial of Service in Oracle Reports Developer

Wed, 26 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allowing Data Manipulation and Denial of Service in Oracle Reports Developer
Weaknesses CWE-284

Wed, 19 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Oracle Reports Developer Unauthenticated Remote Access and Denial of Service Vulnerability
Weaknesses CWE-269
CWE-284

Wed, 19 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Oracle Reports Developer Unauthenticated Remote Access and Denial of Service Vulnerability
Weaknesses CWE-269
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized read access to a subset of Oracle Reports Developer accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:24:13.388Z

Reserved: 2026-07-14T14:54:48.745Z

Link: CVE-2026-62629

cve-icon Vulnrichment

Updated: 2026-08-26T13:52:42.712Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:16.707

Modified: 2026-08-26T17:26:57.497

Link: CVE-2026-62629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:00:14Z

Weaknesses