ZeroHour

CVE-2026-83424

niche

Unauthenticated Data Disclosure in Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83424 is an easily exploitable vulnerability in Oracle JDeveloper, a component of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can trigger the flaw with no user interaction and no privileges required, and a successful attack results in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. The CVSS 3.1 base score is 7.5 (high) with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, meaning the impact is limited to confidentiality (data exposure) with no direct integrity or availability effect. Organizations running the affected JDeveloper versions, particularly any deployment where the tool's HTTP endpoints are reachable by untrusted networks, are at risk. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation is known at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83424 to all installations of JDeveloper 12.2.1.4.0 and 14.1.2.0.0. Ensure JDeveloper's built-in or embedded HTTP endpoints (including any integrated WebLogic test servers) are never reachable from untrusted or internet networks. Review HTTP access logs on affected systems for unauthenticated requests as an indicator of attempted data access.

Affected
Oracle JDeveloper (Oracle Fusion Middleware)
Estimated exposure
nichelikely low tens of thousands of developer installations at most, with minimal internet-exposed instances — Oracle JDeveloper is a free desktop IDE that is not typically deployed as an internet-facing service, and Oracle publishes no active-install counts, so exposure is confined to developers running the two affected versions plus any embedded…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.