CVE-2026-83067
nicheAuthenticated Data Tampering and DoS in Oracle JDeveloper ADF Shared Components
CVE-2026-83067 is a flaw in the ADF Shared Components of Oracle JDeveloper (part of Oracle Fusion Middleware), affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the product via HTTP. A successful attack lets the attacker create, delete, or modify critical data — or all data accessible to Oracle JDeveloper — and to hang or repeatedly crash the product, causing a complete denial of service. The CVSS 3.1 base score is 8.1 (high), driven by high integrity and availability impacts (confidentiality is not affected). No public proof of concept is known and the flaw is not on the CISA KEV catalog, so there is no indication of in-the-wild exploitation.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83067 to JDeveloper 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available for your environment. Restrict HTTP/network access to JDeveloper and ADF endpoints so only trusted developers and hosts can reach them, and enforce least-privilege accounts. Review ADF-accessible data and application logs for unauthorized modifications or unexplained crashes/hangs that could indicate attempted exploitation.
| Oracle JDeveloper (Oracle Fusion Middleware, ADF Shared Components) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle JDeveloper accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.