Junglewise Threat Intelligence

CVE-2026-60352: Oracle JDeveloper information disclosure in ADF Faces

CVE-2026-60352 · Severity: low · CVSS 3.7 · Published 2026-07-21

Technologies: Oracle Jdeveloper. Vendors: Oracle.

Executive brief

Oracle JDeveloper, a development environment used for building enterprise applications, contains a security vulnerability in its ADF Faces component. An unauthenticated attacker could potentially gain unauthorized access to a limited portion of the data managed by the software. While the risk to data confidentiality is present, the vulnerability is considered difficult to exploit and does not allow for the modification of data or disruption of services.

Technical details

A vulnerability exists in the ADF Faces component of Oracle JDeveloper (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw allows an unauthenticated attacker with network access via HTTP to compromise the system, though the attack complexity is rated as high, indicating specific conditions must be met for a successful exploit. If exploited, the attacker can achieve unauthorized read access to a subset of JDeveloper-accessible data. The vulnerability impacts confidentiality but does not affect integrity or availability. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.

Affected products

  • Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats