Junglewise Threat Intelligence

CVE-2026-83067: Oracle JDeveloper data manipulation and denial of service in ADF Shared Components

CVE-2026-83067 · Severity: high · CVSS 8.1 · Published 2026-09-15

Executive brief

Oracle JDeveloper is an integrated development environment used by enterprises to build Java applications. A vulnerability in its ADF Shared Components allows authenticated network attackers to modify or delete critical application data, or crash the development environment entirely. This could disrupt development workflows, corrupt project data, and compromise the integrity of applications under development.

Technical details

The vulnerability exists in Oracle JDeveloper's ADF Shared Components and is exploitable via HTTP by low-privileged authenticated network attackers without user interaction required. The exact vulnerability class is not explicitly stated in the advisory, but the impact encompasses both integrity (unauthorized creation, deletion, or modification of critical data) and availability (denial of service via hang or crash). The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. A patch or update is likely available from Oracle through their standard security patching process, though the reference URL to Oracle's advisory was inaccessible at time of analysis.

Affected products

  • Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats