ZeroHour

CVE-2026-83266

niche

Unauthenticated Data Access Flaw in Oracle JDeveloper Resource Catalog Services

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83266 is a high-severity (CVSS 8.2) vulnerability in the Resource Catalog Services component of Oracle JDeveloper, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker who has network access to the JDeveloper instance via HTTP, requiring no privileges or user interaction. A successful attack allows the attacker to read critical data or all data accessible to Oracle JDeveloper, and to cause a partial denial of service, though integrity is not impacted. Organizations running the affected JDeveloper releases with HTTP-reachable services are exposed, primarily within internal development environments. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation is not currently known.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw and move off JDeveloper 12.2.1.4.0 and 14.1.2.0.0 to the patched release. Restrict network access to JDeveloper and its Resource Catalog Services HTTP endpoints using firewall rules or an allowlist of developer subnets. Review HTTP access logs on affected hosts for unauthenticated requests to resource catalog service paths as an indicator of attempted exploitation.

Affected
Oracle JDeveloper (Oracle Fusion Middleware, Resource Catalog Services)12.2.1.4.0
Oracle JDeveloper (Oracle Fusion Middleware, Resource Catalog Services)14.1.2.0.0
Estimated exposure
nichelikely thousands to tens of thousands of installations; internet-exposed instances rare (order of magnitude: low thousands) — Oracle JDeveloper is a free enterprise IDE typically installed inside corporate development environments rather than exposed to the internet, and no public install counts or internet-scan data are available, so exposure is estimated as…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.