Junglewise Threat Intelligence

CVE-2026-46772: Oracle Application Development Framework improper access control in ADF Faces

CVE-2026-46772 · Severity: medium · CVSS 4.7 · Published 2026-06-17

Technologies: Oracle Application Development Framework. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Application Development Framework (ADF), a tool used by developers to build enterprise applications. A highly privileged attacker who already has access to the underlying server could exploit this flaw to access or modify sensitive business data. While the potential impact on data confidentiality is significant, the attack is difficult to perform and requires existing high-level access to the system.

Technical details

This vulnerability is located in the ADF Faces component of Oracle Application Development Framework (ADF). It is classified as an improper access control issue (CWE-284) that requires the attacker to have high privileges and local logon access to the infrastructure where ADF executes. The attack complexity is rated as high, suggesting specific timing or environmental conditions are necessary for successful exploitation. If successful, an attacker can gain unauthorized access to critical data or perform unauthorized updates and deletions of certain data within the framework. The affected versions are 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle Application Development Framework (ADF) 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD record published

References

Related threats