Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Reports Developer 14.1.2.0.0 allows an unauthenticated attacker who has access to the physical communication segment attached to the hardware where the product runs to take over the application. The weakness is an improper authentication flaw that lets the attacker bypass all credential checks, leading to confidentiality, integrity, and availability compromise. Successful exploitation results in full control over Oracle Reports Developer and allows the attacker to execute arbitrary code on the host system.

Affected Systems

Oracle Reports Developer 14.1.2.0.0, part of Oracle Fusion Middleware, is affected. The vulnerability applies to installations of this specific version of the product and no other versions are mentioned.

Risk and Exploitability

The CVSS score of 8.8 indicates severe impact; however, the exploit requires physical proximity or access to the local network segment connected to the server, which limits the attack surface. EPSS data is not available, so the exact exploitation probability cannot be quantified, but the absence from the CISA KEV catalog suggests there are no known public exploits yet. Nevertheless, because the flaw completely bypasses authentication, the risk to any deployment that is not isolated from physical or local network access is high.

Generated by OpenCVE AI on August 19, 2026 at 01:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Oracle Reports Developer 14.1.2.0.0 as released by Oracle.
  • Restrict physical and local network access to the servers running Oracle Reports Developer by implementing appropriate network segmentation and physical security controls.
  • Ensure that the application is isolated from exposed network interfaces and that unnecessary services are disabled to reduce potential attack vectors.

Generated by OpenCVE AI on August 19, 2026 at 01:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Exploitable Unauthenticated Attack on Oracle Reports Developer via Physical Network Access
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:51.484Z

Reserved: 2026-07-14T14:54:48.746Z

Link: CVE-2026-62631

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:16.930

Modified: 2026-08-18T21:17:16.930

Link: CVE-2026-62631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T01:45:16Z

Weaknesses