Description
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data as well as unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the ADF Faces component of Oracle JDeveloper, permitting attackers who can reach the server over HTTP to read, insert, update, or delete data that the application exposes; no impact on availability is reported. The vulnerability does not require authentication, thereby enabling unauthenticated users to exploit it once network access is obtained.

Affected Systems

Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 are affected. The issue is part of Oracle Fusion Middleware’s ADF Faces component; no other product versions were identified as vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 4.8 indicates low‑to‑moderate severity, primarily affecting confidentiality and integrity. The EPSS score is less than 1 %, implying a very low probability that the flaw will be actively exploited. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attacker must be able to reach the target over HTTP and does not need any credentials; however, the problem is described as difficult to exploit, suggesting that additional conditions (e.g., correct request formatting or specific context) may be required.

Generated by OpenCVE AI on August 2, 2026 at 22:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch available from https://www.oracle.com/security-alerts/cpujul2026.html that addresses the unauthorized data access issue in JDeveloper 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict HTTP access to the JDeveloper instance by firewalling inbound traffic to trusted IPs or by placing the application behind an authenticated reverse proxy.
  • Ensure the ADF Faces component is accessed over HTTPS and enable application-level authentication to prevent unauthenticated users from reaching vulnerable endpoints.

Generated by OpenCVE AI on August 2, 2026 at 22:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Oracle JDeveloper Unauthorized Data Access Vulnerability

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Access in Oracle JDeveloper ADF Faces via HTTP

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Access in Oracle JDeveloper ADF Faces via HTTP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data as well as unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle jdeveloper
CPEs cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jdeveloper
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Jdeveloper
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:45:01.424Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60351

cve-icon Vulnrichment

Updated: 2026-07-24T18:44:39.719Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses