ZeroHour

CVE-2026-83067

niche

Authenticated Data Tampering and DoS in Oracle JDeveloper ADF Shared Components

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83067 is a flaw in the ADF Shared Components of Oracle JDeveloper (part of Oracle Fusion Middleware), affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the product via HTTP. A successful attack lets the attacker create, delete, or modify critical data — or all data accessible to Oracle JDeveloper — and to hang or repeatedly crash the product, causing a complete denial of service. The CVSS 3.1 base score is 8.1 (high), driven by high integrity and availability impacts (confidentiality is not affected). No public proof of concept is known and the flaw is not on the CISA KEV catalog, so there is no indication of in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83067 to JDeveloper 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available for your environment. Restrict HTTP/network access to JDeveloper and ADF endpoints so only trusted developers and hosts can reach them, and enforce least-privilege accounts. Review ADF-accessible data and application logs for unauthorized modifications or unexplained crashes/hangs that could indicate attempted exploitation.

Affected
Oracle JDeveloper (Oracle Fusion Middleware, ADF Shared Components)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
nicheLikely thousands to low tens of thousands of installations (Oracle ADF/JDeveloper developer base), with few internet-exposed instances — JDeveloper is a free, legacy Oracle IDE used mainly by ADF developers (a comparatively small community) and typically runs on developer workstations or internal servers rather than internet-facing hosts, so broad exposure is unlikely.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle JDeveloper accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.