Junglewise Threat Intelligence

CVE-2026-83306: Oracle JDeveloper privilege escalation in Resource Catalog Services

CVE-2026-83306 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Oracle JDeveloper is a development platform used by enterprise teams to build and deploy business applications. A vulnerability in its Resource Catalog Services component allows low-privileged attackers with network access to fully compromise JDeveloper systems, potentially gaining control over development environments, intellectual property, and deployed applications. This poses a significant risk to organizations using JDeveloper for mission-critical development workflows.

Technical details

This is a privilege escalation vulnerability affecting Oracle JDeveloper's Resource Catalog Services component. The vulnerability is easily exploitable via HTTP network access and requires only low-level privileges to trigger; no user interaction is needed. An authenticated attacker can exploit this flaw to gain complete control (confidentiality, integrity, and availability compromise) over the JDeveloper instance. The vulnerability affects JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0. Oracle has issued a patch; users should consult Oracle's security advisory for remediation guidance.

Affected products

  • Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats