Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Reports Developer version 14.1.2.0.0 is vulnerable to an unauthenticated network attack that can be triggered via HTTP. A successful exploitation results in complete takeover of the Report Developer process, compromising confidentiality, integrity, and availability. The weakness is an improper access control flaw within the Security and Authentication component of Oracle Fusion Middleware.

Affected Systems

The affected product is Oracle Reports Developer 14.1.2.0.0, a component of Oracle Fusion Middleware produced by Oracle Corporation.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates a high severity vulnerability with confidentiality, integrity, and availability impact. Exploitation requires network access via HTTP, a high attack complexity, and no privileges or user interaction, making the vulnerability unauthenticated. The EPSS score of < 1% indicates a very low probability of exploitation, though it is not zero, and the issue is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request from an external network capable of reaching the Reports Developer service.

Generated by OpenCVE AI on August 21, 2026 at 11:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Reports Developer patch or upgrade to a fixed version as soon as it is released.
  • Restrict HTTP access to the Reports Developer system by implementing firewall rules or VPN access, limiting connections to trusted networks only.
  • Enable and enforce authentication and role‑based access controls to prevent unauthenticated usage of the Reports Developer service.

Generated by OpenCVE AI on August 21, 2026 at 11:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Enables Compromise of Oracle Reports Developer
Weaknesses CWE-284

Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enables Remote Takeover of Oracle Reports Developer
Weaknesses CWE-284
CWE-710

Wed, 19 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enables Remote Takeover of Oracle Reports Developer
Weaknesses CWE-284
CWE-710

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:13:43.785Z

Reserved: 2026-08-04T22:06:34.588Z

Link: CVE-2026-70675

cve-icon Vulnrichment

Updated: 2026-08-25T14:25:29.592Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:19.267

Modified: 2026-08-26T17:30:14.337

Link: CVE-2026-70675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:15:03Z

Weaknesses