CVE-2026-83424
nicheUnauthenticated Data Disclosure in Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0
CVE-2026-83424 is an easily exploitable vulnerability in Oracle JDeveloper, a component of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can trigger the flaw with no user interaction and no privileges required, and a successful attack results in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. The CVSS 3.1 base score is 7.5 (high) with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, meaning the impact is limited to confidentiality (data exposure) with no direct integrity or availability effect. Organizations running the affected JDeveloper versions, particularly any deployment where the tool's HTTP endpoints are reachable by untrusted networks, are at risk. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation is known at this time.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83424 to all installations of JDeveloper 12.2.1.4.0 and 14.1.2.0.0. Ensure JDeveloper's built-in or embedded HTTP endpoints (including any integrated WebLogic test servers) are never reachable from untrusted or internet networks. Review HTTP access logs on affected systems for unauthenticated requests as an indicator of attempted data access.
| Oracle JDeveloper (Oracle Fusion Middleware) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.