ZeroHour

CVE-2026-83306

niche

Low-Privilege HTTP Takeover Flaw in Oracle JDeveloper Resource Catalog Services

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83306 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Resource Catalog Services component of Oracle JDeveloper, part of Oracle Fusion Middleware. It is easily exploitable by an attacker who already holds low-privileged credentials and has network access to the JDeveloper HTTP interface, requiring no user interaction. Successful exploitation allows the attacker to fully take over the Oracle JDeveloper installation, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0 and 14.1.2.0.0. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83306 to all Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 installations. Restrict HTTP access to JDeveloper and its Resource Catalog Services endpoints to trusted internal networks and enforce least-privilege accounts. Review logs for anomalous activity by low-privileged users against catalog services that could indicate exploitation attempts.

Affected
Oracle JDeveloper (Oracle Fusion Middleware, Resource Catalog Services)
Estimated exposure
nicheunknown; plausibly on the order of hundreds to low thousands of internet-reachable instances, plus a larger but unquantifiable set of internal development… — JDeveloper is a developer IDE typically run on internal workstations or development servers rather than internet-facing production systems, and public scan data rarely shows exposed JDeveloper/Resource Catalog Services endpoints.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.