Executive brief
Oracle JDeveloper, a development environment for building Java-based applications, contains a security vulnerability in its ADF Faces component. A low-privileged user could potentially gain unauthorized access to a limited amount of sensitive data within the system. While the impact is restricted to data confidentiality, it represents a risk to the privacy of information managed within the development environment.
Technical details
A vulnerability in the ADF Faces component of Oracle JDeveloper (versions 12.2.1.4.0 and 14.1.2.0.0) allows an authenticated, low-privileged attacker with network access via HTTP to compromise the system. The vulnerability is characterized by high attack complexity, suggesting specific conditions or configurations must be met for successful exploitation. If exploited, the attacker can achieve unauthorized read access to a subset of Oracle JDeveloper accessible data, impacting confidentiality. No integrity or availability impacts are reported. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update
- 2026-07-21: advisory: NVD entry published