Junglewise Threat Intelligence

CVE-2026-60629: Oracle JDeveloper data access vulnerability in Data Visualization Tools

CVE-2026-60629 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Jdeveloper. Vendors: Oracle.

Executive brief

Oracle JDeveloper, a development environment used for building Java applications, contains a vulnerability in its Data Visualization Tools component. An attacker could exploit this flaw to gain unauthorized access to sensitive data or modify information within the system. Because this tool is integrated with other enterprise software, a successful attack could also impact the security of connected business applications.

Technical details

A vulnerability exists in the Data Visualization Tools component of Oracle JDeveloper (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is exploitable by an unauthenticated attacker via the HTTP protocol, though Oracle notes the attack complexity is high. A successful exploit results in a scope change (S:C), meaning the impact can extend beyond JDeveloper to other integrated products. Attackers can achieve full read access to all accessible data and partial unauthorized update, insert, or delete capabilities. The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats