CVE-2026-62637: Critical severity Oracle Oracle Reports Developer vulnerability
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Oracle Reports Developer version 14.1.2.0.0 is identified as affected. Exploitation requires access to the physical communication segment attached to the hardware running Oracle Reports Developer, so exposure is tied to attackers able to reach that local network segment.
Does an attacker need credentials or user interaction?
No. The vulnerability is described as easily exploitable by an unauthenticated attacker, and no user interaction is required.
What could a successful attacker do?
A successful attack can provide unauthorized access to critical data or all data accessible to Oracle Reports Developer, and can allow creation, deletion, or modification of that data. The scope change means impacts may significantly extend to additional products.
What is the practical mitigation if remediation cannot be applied immediately?
Restrict access to the physical communication segment connected to the affected Oracle Reports Developer host. This directly limits the attacker access condition stated for exploitation.