EIP-2026-104038
PRE-CVEOracle Reports Server 6.0.8/9.0.x - Unauthorized Report Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104038. PoCs published by Alexander Kornbrust.
AI-analyzed exploit summary The vulnerability allows unauthorized execution of Oracle Reports by placing a malicious report file in a globally accessible location and triggering it via an HTTP GET request. This can lead to arbitrary command execution or file read/write operations with Oracle server privileges.
Description
Oracle Reports Server 6.0.8/9.0.x - Unauthorized Report Execution
Exploits (1)
The vulnerability allows unauthorized execution of Oracle Reports by placing a malicious report file in a globally accessible location and triggering it via an HTTP GET request. This can lead to arbitrary command execution or file read/write operations with Oracle server privileges.