Junglewise Threat Intelligence

CVE-2026-46769: Oracle ADF improper access control in ADF Shared Components

CVE-2026-46769 · Severity: high · CVSS 7.2 · Published 2026-06-17

Technologies: Oracle Application Development Framework. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Application Development Framework (ADF), a tool used by developers to build enterprise applications. A high-privileged attacker could exploit this flaw to gain full control over the framework. This could lead to a complete compromise of the applications built on this framework, potentially resulting in data theft or service disruption.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the ADF Shared Components of Oracle Fusion Middleware. It is easily exploitable by a high-privileged attacker with network access via HTTP. The flaw allows for a complete takeover of the Oracle Application Development Framework, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Application Development Framework (ADF) 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats