ZeroHour

CVE-2026-73961

niche

Unauthenticated Takeover Flaw in Oracle JDeveloper ADF Faces (Fusion Middleware)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73961 is a critical vulnerability (CVSS 3.1 base score 9.8) in the ADF Faces component of Oracle JDeveloper, part of Oracle Fusion Middleware. The flaw is easily exploitable by an unauthenticated attacker who has network access via HTTP, requiring no privileges and no user interaction. A successful attack can result in complete takeover of the Oracle JDeveloper installation, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0 and 14.1.2.0.0. No public proof-of-concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-73961 to all JDeveloper 12.2.1.4.0 and 14.1.2.0.0 installations as soon as it is available. Restrict HTTP network access to JDeveloper and associated development servers so they are reachable only from trusted internal networks. Audit those systems for signs of unauthenticated HTTP access or unexpected configuration changes until patched.

Affected
Oracle JDeveloper (Oracle Fusion Middleware, component: ADF Faces)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
nicheunknown; likely low thousands to tens of thousands of developer installations, with very few internet-exposed instances — Oracle JDeveloper is a specialized Java IDE used mainly for Oracle ADF/WebLogic development on internal workstations and development servers rather than internet-facing deployments, and no public install counts or exposed-device scan data…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.