CVE-2026-73961
nicheUnauthenticated Takeover Flaw in Oracle JDeveloper ADF Faces (Fusion Middleware)
CVE-2026-73961 is a critical vulnerability (CVSS 3.1 base score 9.8) in the ADF Faces component of Oracle JDeveloper, part of Oracle Fusion Middleware. The flaw is easily exploitable by an unauthenticated attacker who has network access via HTTP, requiring no privileges and no user interaction. A successful attack can result in complete takeover of the Oracle JDeveloper installation, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0 and 14.1.2.0.0. No public proof-of-concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-73961 to all JDeveloper 12.2.1.4.0 and 14.1.2.0.0 installations as soon as it is available. Restrict HTTP network access to JDeveloper and associated development servers so they are reachable only from trusted internal networks. Audit those systems for signs of unauthenticated HTTP access or unexpected configuration changes until patched.
| Oracle JDeveloper (Oracle Fusion Middleware, component: ADF Faces) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.