CVE-2026-83306
nicheLow-Privilege HTTP Takeover Flaw in Oracle JDeveloper Resource Catalog Services
CVE-2026-83306 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Resource Catalog Services component of Oracle JDeveloper, part of Oracle Fusion Middleware. It is easily exploitable by an attacker who already holds low-privileged credentials and has network access to the JDeveloper HTTP interface, requiring no user interaction. Successful exploitation allows the attacker to fully take over the Oracle JDeveloper installation, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0 and 14.1.2.0.0. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83306 to all Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 installations. Restrict HTTP access to JDeveloper and its Resource Catalog Services endpoints to trusted internal networks and enforce least-privilege accounts. Review logs for anomalous activity by low-privileged users against catalog services that could indicate exploitation attempts.
| Oracle JDeveloper (Oracle Fusion Middleware, Resource Catalog Services) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.