Junglewise Threat Intelligence

CVE-2026-60348: Oracle JDeveloper information disclosure in ADF Faces

CVE-2026-60348 · Severity: medium · CVSS 5.9 · Published 2026-07-21

Technologies: Oracle Jdeveloper. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle JDeveloper's ADF Faces component, which is used for building enterprise web applications. An attacker could exploit this flaw to gain unauthorized access to sensitive business data. While the attack is difficult to execute, a successful breach could compromise all data accessible by the JDeveloper environment.

Technical details

A vulnerability in the ADF Faces component of Oracle JDeveloper (Oracle Fusion Middleware) allows an unauthenticated attacker with network access via HTTP to compromise the system. The vulnerability is characterized by high attack complexity, suggesting specific timing or environmental conditions are required for successful exploitation. If exploited, the attacker can achieve unauthorized access to critical data or complete access to all data accessible by JDeveloper. The issue affects versions 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats