Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Reports Developer contains a flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The vulnerability enables full takeover of the service, potentially allowing an attacker to run arbitrary code or gain complete control, resulting in loss of confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects Oracle Reports Developer version 14.1.2.0.0, part of Oracle Fusion Middleware. This is the only supported release identified as impacted, and the weakness resides in the Security and Authentication component.

Risk and Exploitability

The CVSS v3.1 base score of 9.8 signifies very high severity. The EPSS score of < 1% indicates that, while exploitation probability is low, the lack of authentication and the simple HTTP request required make the vulnerability a realistic threat for systems exposed to untrusted traffic. The vulnerability is not cataloged in CISA’s KEV, but its high score warrants urgent attention.

Generated by OpenCVE AI on August 27, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for Oracle Reports Developer 14.1.2.0.0 or upgrade to a fixed release that contains the fix.
  • Restrict or block direct HTTP access to the Reports Developer service from external or untrusted networks using firewall rules or routing policies to reduce exposure.
  • Enforce robust authentication and secure configuration on Reports Developer, including disabling default accounts and requiring strong passwords to prevent unauthenticated access.

Generated by OpenCVE AI on August 27, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP RCE in Oracle Reports Developer

Wed, 26 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Oracle Reports Developer Vulnerability: Unauthenticated HTTP Compromise
Weaknesses CWE-287
CWE-94

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Oracle Reports Developer Vulnerability: Unauthenticated HTTP Compromise
Weaknesses CWE-287
CWE-94

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T17:34:44.690Z

Reserved: 2026-07-14T14:54:48.746Z

Link: CVE-2026-62633

cve-icon Vulnrichment

Updated: 2026-08-26T17:25:12.351Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:17.153

Modified: 2026-08-26T18:16:55.000

Link: CVE-2026-62633

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T00:30:14Z

Weaknesses