Description
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Partial Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Resource Catalog Services component of Oracle JDeveloper, where an unauthenticated attacker can send specially crafted HTTP requests over the network. If successfully exploited, the attacker can read sensitive configuration data, gain full access to all data exposed by JDeveloper, and induce a partial denial of service, lowering system availability. This weakness is effectively an improper access control flaw that permits unauthorized privileges without authentication.

Affected Systems

Oracle JDeveloper products from Oracle Corporation, specifically version 12.2.1.4.0 and 14.1.2.0.0, are impacted. No other supported versions were identified in the advisory.

Risk and Exploitability

The vulnerability carries a CVSS v3.1 base score of 8.2, indicating high confidentiality impact and moderate availability impact. The EPSS score is less than 1 percent, suggesting that, as of the analysis, the likelihood of exploitation in the wild is low. However, the advisory lists the vulnerability as exploitable by unauthenticated users over HTTP, meaning an attacker with network access to the JDeveloper instance could potentially compromise data confidentiality and disrupt services. The vulnerability is not currently listed in the CISA KEV catalog, but its high severity warrants prompt remediation.

Generated by OpenCVE AI on September 21, 2026 at 23:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest security patch for Oracle JDeveloper 12.2.1.4.0 or 14.1.2.0.0, as provided by Oracle's security alerts.
  • When a patch is unavailable or cannot be applied immediately, restrict HTTP access to the JDeveloper server by implementing firewall rules or placing it behind a VPN so that only trusted hosts can reach the Resource Catalog Services.
  • Disable or restrict the Resource Catalog Services if they are not required for operations, ensuring that no unauthenticated endpoints remain exposed.

Generated by OpenCVE AI on September 21, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Enables Unauthorized Data Access and Partial Denial of Service in Oracle JDeveloper

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access in Oracle JDeveloper Resource Catalog Services Allows Data Disclosure and Partial Denial of Service
Weaknesses CWE-284
CWE-286

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access in Oracle JDeveloper Resource Catalog Services Allows Data Disclosure and Partial Denial of Service
Weaknesses CWE-284
CWE-286

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access and Partial Denial in Oracle JDeveloper
Weaknesses CWE-284

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access and Partial Denial in Oracle JDeveloper
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle jdeveloper
CPEs cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jdeveloper
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Jdeveloper
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:30:12.414Z

Reserved: 2026-08-31T15:40:57.350Z

Link: CVE-2026-83266

cve-icon Vulnrichment

Updated: 2026-09-21T19:29:53.751Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:38.957

Modified: 2026-09-21T20:17:33.273

Link: CVE-2026-83266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T00:00:13Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function