CVE-2026-83423
nicheAuthenticated Remote Takeover Flaw in Oracle JDeveloper Security Framework
Oracle JDeveloper, part of Oracle Fusion Middleware, contains a high-severity vulnerability (CVSS 8.8) in its Security Framework component affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker who already holds low-privileged credentials and can reach the product over HTTP can exploit the flaw easily, without user interaction, and gain full control of the Oracle JDeveloper installation. Successful compromise results in complete impacts to confidentiality, integrity, and availability of the affected system. Organizations running the affected JDeveloper releases in network-accessible development or build environments are the primary exposure. There is no known public proof of concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so no active exploitation has been observed.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83423 to all Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 installations. Restrict HTTP network access to JDeveloper instances so only trusted developers and networks can reach them, since exploitation requires an authenticated low-privileged session. Review logs on affected systems for anomalous authenticated activity, as successful attacks result in full takeover.
| Oracle JDeveloper (Oracle Fusion Middleware, Security Framework component) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.