Executive brief
Oracle JDeveloper is a development environment used by software engineers to build enterprise applications. An unauthenticated attacker can exploit this flaw over the network to read sensitive project data and disrupt service availability, without requiring login credentials or user interaction.
Technical details
This is an authentication bypass vulnerability in the Resource Catalog Services component of Oracle JDeveloper. The flaw is easily exploitable via HTTP and requires no authentication, no special configuration, and no user interaction. An attacker with network access can directly access the vulnerable service and either extract critical data or cause partial denial of service. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. Oracle has published a security advisory (CSP September 2026) addressing this issue; patch availability should be confirmed through the official advisory.
Affected products
- Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed