Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-62608: Oracle Reports Developer Security Flaw on Oracle Fusion Middleware

CVE-2026-62608 · published 16 days ago
Summary

A security flaw in Oracle Reports Developer on Oracle Fusion Middleware 12.2.1.19.0 allows an attacker with network access to take control of the system. This could impact other products as well. Oracle recommends updating to a newer version to prevent exploitation.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
oracle corporation oracle reports developer 12.2.1.19.0
Original advisory text
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitab...
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via CORBA to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Timeline
Published18 Aug 2026
Updated1 Sep 2026
First seen18 Aug 2026
Sources
CVE-2026-62608 · MITRE
Monitor software like this
Free during beta