CVE-2026-70670: Critical severity Oracle Oracle Reports Developer vulnerability
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker must have access to the physical communication segment attached to the hardware running Oracle Reports Developer. The attack requires no user interaction and has low attack complexity.
Which release is identified as affected?
The affected supported version identified is Oracle Reports Developer 14.1.2.0.0.
What is the potential operational impact of a successful attack?
A successful attack can result in takeover of Oracle Reports Developer, with high confidentiality, integrity, and availability impact. The scope change indicates attacks may also significantly affect additional products.