Description
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Restrict Access
AI Analysis

Impact

A flaw in the Resource Catalog Services component of Oracle JDeveloper allows an attacker with low privileges to communicate over HTTP and achieve a full compromise of the JDeveloper instance, leading to loss of confidentiality, integrity, and availability. The vulnerability is easily exploitable from the network and requires no user interaction beyond normal HTTP requests. Successful exploitation enables an attacker to take control of the JDeveloper environment.

Affected Systems

Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware and are supported under the indicated product lines.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates high severity, but the EPSS score of less than 1 % suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, further indicating limited active exploitation. The attack can be launched via standard HTTP network access and only requires low‑privileged credentials, resulting in full compromise of the JDeveloper instance when successful.

Generated by OpenCVE AI on September 20, 2026 at 08:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Consult the Oracle security alert for this vulnerability and apply any Oracle JDeveloper patches that are released for versions 12.2.1.4.0 and 14.1.2.0.0.
  • Limit external HTTP access to the JDeveloper service so that only trusted administrators can reach it, using firewall rules or network segmentation.
  • If the Resource Catalog Services component is not required, remove or disable it to eliminate the exposure.

Generated by OpenCVE AI on September 20, 2026 at 08:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploitation Enables Full Compromise of Oracle JDeveloper

Fri, 18 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title HTTP-based takeover vulnerability in Oracle JDeveloper
Weaknesses CWE-284
CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title HTTP-based takeover vulnerability in Oracle JDeveloper
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jdeveloper
CPEs cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jdeveloper
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jdeveloper
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:27.334Z

Reserved: 2026-08-31T15:40:57.352Z

Link: CVE-2026-83306

cve-icon Vulnrichment

Updated: 2026-09-17T13:00:04.200Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:43.530

Modified: 2026-09-17T14:17:40.723

Link: CVE-2026-83306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management