CVE-2026-83266
nicheUnauthenticated Data Access Flaw in Oracle JDeveloper Resource Catalog Services
CVE-2026-83266 is a high-severity (CVSS 8.2) vulnerability in the Resource Catalog Services component of Oracle JDeveloper, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker who has network access to the JDeveloper instance via HTTP, requiring no privileges or user interaction. A successful attack allows the attacker to read critical data or all data accessible to Oracle JDeveloper, and to cause a partial denial of service, though integrity is not impacted. Organizations running the affected JDeveloper releases with HTTP-reachable services are exposed, primarily within internal development environments. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation is not currently known.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw and move off JDeveloper 12.2.1.4.0 and 14.1.2.0.0 to the patched release. Restrict network access to JDeveloper and its Resource Catalog Services HTTP endpoints using firewall rules or an allowlist of developer subnets. Review HTTP access logs on affected hosts for unauthenticated requests to resource catalog service paths as an indicator of attempted exploitation.
| Oracle JDeveloper (Oracle Fusion Middleware, Resource Catalog Services) | 12.2.1.4.0 |
| Oracle JDeveloper (Oracle Fusion Middleware, Resource Catalog Services) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.