Description
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle JDeveloper accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification and Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A flaw exists in the ADF Shared Components of Oracle JDeveloper that permits an attacker with network access via HTTP to create, delete, or modify critical data without proper authorization. The vulnerability can also lead to application hangs or repeated crashes, providing a means to interrupt service availability. The flaw is a direct result of privileged access control weaknesses, allowing a low privileged attacker to alter or overwhelm data integrity and availability.

Affected Systems

Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability resides within the Oracle Fusion Middleware ADF Shared Components component and impacts only the specified releases.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates high severity with integrity and availability impacts. The EPSS score of less than 1% shows a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over HTTP; a low privileged attacker who can reach the JDeveloper HTTP interface could exploit the lack of proper authorization checks to modify or delete data and force the application to crash.

Generated by OpenCVE AI on September 20, 2026 at 10:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle JDeveloper patch or upgrade to a non‑vulnerable release according to Oracle Security Alert CSPUSEP2026.
  • Limit HTTP access to the JDeveloper application by firewall or reverse proxy so that only trusted hosts or authenticated users can reach the service.
  • Review and enforce proper access‑control configuration on the ADF Shared Components to prevent unauthorized creation, deletion, or modification of data.

Generated by OpenCVE AI on September 20, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Data Modification and Denial-of-Service in Oracle JDeveloper ADF Shared Components

Thu, 17 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Data Modification and Denial-of-Service in Oracle JDeveloper ADF Shared Components

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle JDeveloper accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
First Time appeared Oracle
Oracle jdeveloper
CPEs cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jdeveloper
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Oracle Jdeveloper
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:59:31.454Z

Reserved: 2026-08-31T15:40:57.337Z

Link: CVE-2026-83067

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:39.254Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:15.550

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:30:17Z

Weaknesses