Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-62608: Oracle Reports Developer Security Flaw on Oracle Fusion Middleware
CVE-2026-62608 · published 16 days ago
Summary
A security flaw in Oracle Reports Developer on Oracle Fusion Middleware 12.2.1.19.0 allows an attacker with network access to take control of the system. This could impact other products as well. Oracle recommends updating to a newer version to prevent exploitation.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| oracle corporation | oracle reports developer | 12.2.1.19.0 |
Original advisory text
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitab...
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via CORBA to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
References
- https://www.oracle.com/security-alerts/cspuaug2026.html vendor-advisory
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Timeline
Published18 Aug 2026
Updated1 Sep 2026
First seen18 Aug 2026
Monitor software like this
Free during beta