Description
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Development Framework (ADF) executes to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Development Framework (ADF) accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Development Framework (ADF) accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-06-16
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is described as difficult to exploit and allows a high‑privileged attacker who is already a logon user on the infrastructure where Oracle Application Development Framework (ADF) runs to compromise that framework. When exploited, the attacker can obtain unauthorized access to critical data or all data that ADF can access, as well as perform unauthorized updates, inserts or deletions. The CVSS 3.1 score of 4.7 indicates moderate impact on confidentiality and a low but non‑zero impact on integrity.

Affected Systems

Affected products are Oracle Corporation’s Oracle Application Development Framework (ADF) component of Oracle Fusion Middleware, specifically the ADF Faces part. The vulnerable releases are 12.2.1.4.0 and 14.1.2.0.0.

Risk and Exploitability

Because the attack requires local access (AV:L) and high privileges (PR:H) and does not require user interaction (UI:N), the EPSS score is reported as less than 1 %. The vulnerability is not listed in the CISA KEV catalog, which indicates no known active exploitation. However, if an attacker gains local high‑privileged access, they can achieve significant data exposure or modification. The moderate CVSS score reflects that while the vulnerability is not trivial, it carries real risk if the prerequisites for exploitation are met.

Generated by OpenCVE AI on June 17, 2026 at 19:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether your installation uses Oracle ADF 12.2.1.4.0 or 14.1.2.0.0 and if so, check for and apply the latest Oracle security patch or upgrade to a non‑affected version when it becomes available.
  • Limit local privileged accounts to the minimum set of users required for operation and enforce least‑privilege principles for all system accounts.
  • Monitor logs for anomalous database activity or repeated attempts to access ADF faces components, and investigate any unauthorized data changes promptly.

Generated by OpenCVE AI on June 17, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Development Framework (ADF) executes to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Development Framework (ADF) accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Development Framework (ADF) accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle application Development Framework
CPEs cpe:2.3:a:oracle:application_development_framework:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:application_development_framework:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Development Framework
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Application Development Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:34:26.970Z

Reserved: 2026-05-18T15:55:10.296Z

Link: CVE-2026-46772

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T23:45:14Z

Weaknesses

No weakness.