Description
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper. While the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle JDeveloper contains a local authorization bypass flaw in its ADF Faces component (CWE-200), allowing an attacker with low‑privileged access to the host to read or manipulate data exposed by the application. The vulnerability does not require network interaction and achieves a confidentiality compromise, potentially affecting all data that JDeveloper can access. Because the flaw can cause a scope change, compromising one installation may allow access to related Oracle services.

Affected Systems

Oracle JDeveloper version 12.2.1.4.0 and 14.1.2.0.0 from Oracle Corporation are affected. These releases are actively supported and can be identified via the supplied CPE strings. The flaw exists in the ADF Faces component of the product.

Risk and Exploitability

CVSS 6.5, EPSS <1%. Attack requires local access (AV:L) and low privileges (PR:L). The flaw is not listed in CISA KEV but could be exploited by someone who already has a local account, allowing them to read all JDeveloper‑exposed data and potentially impact other Oracle services through a scope change. The low EPSS score indicates a low likelihood of widespread exploitation in the wild.

Generated by OpenCVE AI on August 4, 2026 at 04:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to the latest patched release that addresses this CVE.
  • Enforce the principle of least privilege on the host by restricting local accounts used for JDeveloper, ensuring they have only required rights.
  • Address the CWE-200 Information Exposure weakness by limiting access to sensitive information and disabling unnecessary debug or error outputs that could expose data.
  • Activate detailed auditing of JDeveloper data access, inspecting logs for unauthorized reads or modifications.

Generated by OpenCVE AI on August 4, 2026 at 04:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Oracle JDeveloper

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Oracle JDeveloper
Weaknesses CWE-284
CWE-285

Mon, 27 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Access in Oracle JDeveloper ADF Faces Allows Unauthorized Data Access

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Low Privilege Access in Oracle JDeveloper ADF Faces Allows Unauthorized Data Access
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper. While the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle jdeveloper
CPEs cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jdeveloper
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Jdeveloper
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:46:05.485Z

Reserved: 2026-07-08T15:51:40.531Z

Link: CVE-2026-60350

cve-icon Vulnrichment

Updated: 2026-07-24T18:46:00.340Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor