Executive brief
Oracle JDeveloper, a development environment used for building enterprise applications, contains a vulnerability in its Application Development Framework (ADF) components. A high-privileged attacker can exploit this flaw over a network to gain full control of the JDeveloper environment. This could lead to the unauthorized access, modification, or deletion of sensitive application source code and development data.
Technical details
A vulnerability exists in the ADF Shared Components of Oracle JDeveloper (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle JDeveloper instance, impacting confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
- 2026-07-21: disclosed: CVE-2026-60345 was published to the NVD.