Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Reports Developer version 14.1.2.0.0 is vulnerable to an unauthenticated network attack that can be triggered via HTTP. A successful exploitation results in complete takeover of the Report Developer process, compromising confidentiality, integrity, and availability. The weakness falls under improper access control orchestrated through the Security and Authentication component of Oracle Fusion Middleware.

Affected Systems

The affected product is Oracle Reports Developer 14.1.2.0.0, a component of Oracle Fusion Middleware produced by Oracle Corporation.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates a high severity vulnerability with confidentiality, integrity, and availability impact. Exploitation requires network access (HTTP) and high attack complexity but no privileges or user interaction, and it is unauthenticated. No EPSS score is publicly available, and the issue is not yet listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request from an external network capable of reaching the Reports Developer service.

Generated by OpenCVE AI on August 19, 2026 at 01:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Reports Developer patch or upgrade to a fixed version as soon as it is released.
  • Restrict HTTP access to the Reports Developer system by implementing firewall rules or VPN access, limiting connections to trusted networks only.
  • Enable and enforce authentication and role‑based access controls to prevent unauthenticated usage of the Reports Developer service.

Generated by OpenCVE AI on August 19, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enables Remote Takeover of Oracle Reports Developer
Weaknesses CWE-284
CWE-710

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:57.066Z

Reserved: 2026-08-04T22:06:34.588Z

Link: CVE-2026-70675

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:19.267

Modified: 2026-08-18T21:17:19.267

Link: CVE-2026-70675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T01:30:05Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-710

    Improper Adherence to Coding Standards