Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Reports Developer 14.1.2.0.0 allows an attacker who can reach the system over HTTP to gain complete control of the application without needing credentials. This results in the loss of confidentiality, integrity, and availability for all data managed by the Reports Developer environment. The weakness is a form of authentication bypass that permits unrestricted access.

Affected Systems

Oracle Reports Developer 14.1.2.0.0 delivered as part of Oracle Fusion Middleware. No other product or version is listed as affected.

Risk and Exploitability

The CVSS score of 9.8 marks this flaw as critical. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation. The lack of a requirement for privileged access and the requirement only of public network connectivity make exploitation highly feasible. The vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities catalog, but its characteristics suggest that attackers could prepare a publicly available exploit quickly.

Generated by OpenCVE AI on August 27, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest security patch or upgrade to a release that contains the fix for this flaw.
  • Configure the network perimeter to block all inbound HTTP traffic to Oracle Reports Developer except from trusted systems or over a VPN.
  • Disable or remove any unused extensions, services, or exposed interfaces that could provide additional attack vectors.

Generated by OpenCVE AI on August 27, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Oracle Reports Developer 14.1.2.0.0 Unauthenticated Remote Takeover via HTTP
Weaknesses CWE-287

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Oracle Reports Developer 14.1.2.0.0 Unauthenticated Remote Takeover via HTTP
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T17:34:44.864Z

Reserved: 2026-07-14T14:54:48.746Z

Link: CVE-2026-62632

cve-icon Vulnrichment

Updated: 2026-08-26T17:25:14.127Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:17.043

Modified: 2026-08-26T18:16:54.543

Link: CVE-2026-62632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T00:30:14Z

Weaknesses