Junglewise Threat Intelligence

CVE-2026-83424: Oracle JDeveloper unauthorized information disclosure

CVE-2026-83424 · Severity: high · CVSS 7.5 · Published 2026-09-15

Executive brief

Oracle JDeveloper is an integrated development environment used by enterprises to build Java and web applications. An unauthenticated network attacker can exploit this vulnerability to access sensitive source code, configuration data, and other critical information stored within JDeveloper projects without providing valid credentials.

Technical details

This is an information disclosure vulnerability in Oracle JDeveloper that allows unauthenticated attackers to gain unauthorized access to critical data through the HTTP interface. The vulnerability requires no user interaction and is easily exploitable from the network. An attacker with unauthenticated network access via HTTP can retrieve sensitive project data and confidential information accessible to JDeveloper. No integrity or availability impact is present, only confidentiality is affected. Oracle has identified affected versions 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats