Junglewise Threat Intelligence

CVE-2026-60345: Oracle JDeveloper takeover in ADF Shared Components

CVE-2026-60345 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle Jdeveloper. Vendors: Oracle.

Executive brief

Oracle JDeveloper, a development environment used for building enterprise applications, contains a vulnerability in its Application Development Framework (ADF) components. A high-privileged attacker can exploit this flaw over a network to gain full control of the JDeveloper environment. This could lead to the unauthorized access, modification, or deletion of sensitive application source code and development data.

Technical details

A vulnerability exists in the ADF Shared Components of Oracle JDeveloper (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle JDeveloper instance, impacting confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
  • 2026-07-21: disclosed: CVE-2026-60345 was published to the NVD.

References

Related threats