LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-70670

oracle · reports developer

Published
CVSS9.6
Severitycritical
WeaknessNVD-CWE-noinfo
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts

References

← Back to the CVE Tracker

Our coverage of CVE-2026-70670

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-70670.