Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that an attacker who physically accesses the hardware communication segment of Oracle Reports Developer can create, delete, or modify data and read all data accessible to the application. This is an improper authorization (CWE‑284) bypass that allows unauthenticated local attackers to bypass security controls and alter or retrieve any data the application holds. The vulnerability, rated 9.3 on CVSS 3.1, imposes full confidentiality and integrity breach with no availability impact.

Affected Systems

Oracle Reports Developer for Oracle Fusion Middleware, specifically version 14.1.2.0.0. The issue in this component may also affect other products that share or rely on the same security and authentication mechanisms due to a potential scope change.

Risk and Exploitability

The high CVSS score reflects significant risk, and based on the description it is inferred that the likely attack vector is local or near‑local physical access to the communication segment, as indicated by the adjacent network vector (AV:A), requiring local or near‑local physical presence and is otherwise easily exploitable. The EPSS score is less than 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, yet its severity warrants urgent attention. An attacker can leverage the flaw to gain unauthorized creation, deletion, modification, or reading of data, impacting confidentiality and integrity across the affected system and potentially other products that share the authentication boundary.

Generated by OpenCVE AI on August 27, 2026 at 01:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Reports Developer to the latest patched version that addresses the CVSS 9.3 vulnerability.
  • Implement strict physical security controls to prevent unauthorized personnel from accessing the communication segment where Oracle Reports Developer runs.
  • If a patch cannot be applied immediately, isolate or disable the affected interfaces and monitor system logs for any indicator of suspicious data access or modification.

Generated by OpenCVE AI on August 27, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Local Physical Access Exploit in Oracle Reports Developer Allows Unauthorized Data Modification

Thu, 27 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Local Unauthenticated Access Enables Data Modification in Oracle Reports Developer
Weaknesses CWE-287

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Local Unauthenticated Access Enables Data Modification in Oracle Reports Developer
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T17:34:44.531Z

Reserved: 2026-07-14T14:54:48.746Z

Link: CVE-2026-62637

cve-icon Vulnrichment

Updated: 2026-08-26T17:25:10.521Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:17.620

Modified: 2026-08-26T18:16:55.463

Link: CVE-2026-62637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T02:00:14Z

Weaknesses