Description
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local vulnerability within the Oracle JDeveloper Security Framework allows an attacker who is already logged on to JDeveloper’s host to compromise the application, resulting in loss of confidentiality, integrity, and availability of JDeveloper services. The CVSS 3.1 base score of 7.0 reflects these combined impacts. The weakness is of a type that grants the attacker broader control of the JDeveloper environment once accessed.

Affected Systems

Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 are known to be affected by this flaw.

Risk and Exploitability

The CVSS 3.1 base score of 7.0 indicates a high severity impact on confidentiality, integrity, and availability, reflecting moderate to high risk for the affected application. The EPSS score indicates a very low but non‑zero chance of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, requiring the attacker to have logon access to the infrastructure where JDeveloper runs; no remote trigger is available. Given the low exploitation probability and the local nature, the primary risk is to users who can obtain local accounts, rather than a widespread, automated attack surface.

Generated by OpenCVE AI on August 4, 2026 at 01:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the Oracle security patch for JDeveloper 12.2.1.4.0 and 14.1.2.0.0 from the Oracle security response center to remediate the flaw
  • Restrict local user access to the JDeveloper host by implementing least‑privilege and role‑based restrictions
  • Monitor JDeveloper logs and system activity for signs of local compromise and review alert thresholds

Generated by OpenCVE AI on August 4, 2026 at 01:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle JDeveloper Allows Application Takeover

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Oracle JDeveloper Local Vulnerability Allows Application Takeover
Weaknesses CWE-284

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Oracle JDeveloper Local Vulnerability Allows Application Takeover
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jdeveloper
CPEs cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jdeveloper
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jdeveloper
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:20:08.802Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61061

cve-icon Vulnrichment

Updated: 2026-07-24T14:20:03.053Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management