Executive brief
Oracle JDeveloper is a development tool used by enterprises to build Java applications. This vulnerability in the ADF Faces component allows an unauthenticated attacker on the network to remotely take over the entire system without requiring any user interaction. Successful exploitation results in complete compromise of confidentiality, integrity, and availability—meaning attackers can access sensitive code and data, modify applications, and disrupt development operations.
Technical details
This is a network-accessible remote code execution vulnerability in the ADF Faces component of Oracle JDeveloper, exploitable without authentication or user interaction. The vulnerability allows an unauthenticated attacker with network access via HTTP to achieve complete system compromise. The attack has low complexity (no special conditions required) and impacts all three security pillars: confidentiality, integrity, and availability. Patch availability from Oracle has not been confirmed from the provided advisory text.
Affected products
- Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed