CVE-2026-35243: High severity Oracle Application Development Framework (ADF) vulnerability
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Application Development Framework (ADF) executes to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35243?
CVE-2026-35243 is classified as an easily exploitable vulnerability that poses significant risks if targeted.
How do I fix CVE-2026-35243?
To fix CVE-2026-35243, upgrade your Oracle Application Development Framework (ADF) to version 12.2.1.4.0 or 14.1.2.0.0 as applicable.
What versions are affected by CVE-2026-35243?
The versions affected by CVE-2026-35243 are 12.2.1.4.0 and 14.1.2.0.0 of Oracle Application Development Framework.
Who is at risk from CVE-2026-35243?
Low privileged attackers with logon access to the infrastructure are at risk of exploiting CVE-2026-35243.
Is there a workaround for CVE-2026-35243?
Currently, the best approach for CVE-2026-35243 is to apply the recommended patches or upgrades, as specific workarounds are not provided.