CVE-2026-46769: High severity Oracle Oracle Application Development Framework vulnerability
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle Application Development Framework (ADF) HTTP endpoints: block or limit HTTP access to ADF servers using firewall rules or ACLs to trusted IPs only, place ADF behind a Web Application Firewall (WAF), and remove direct internet access. Apply network segmentation to isolate ADF components from untrusted networks.
- Operational
Monitor ADF logs and network traffic for suspicious activity targeting HTTP endpoints. If compromise is suspected, isolate affected systems for investigation, perform forensics, rotate any potentially exposed credentials or keys, and apply vendor-supplied patches or updates as soon as Oracle publishes fixes.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46769?
The severity of CVE-2026-46769 is rated as high with a score of 7.2.
How do I fix CVE-2026-46769?
To fix CVE-2026-46769, upgrade to a patched version of Oracle Application Development Framework not affected by this vulnerability.
What are the affected versions for CVE-2026-46769?
The affected versions for CVE-2026-46769 are 12.2.1.4.0 and 14.1.2.0.0 of Oracle Application Development Framework.
Who is affected by CVE-2026-46769?
High privileged attackers with network access via HTTP can exploit CVE-2026-46769.
What is the impact of CVE-2026-46769?
The impact of CVE-2026-46769 includes potential full data compromise due to extensive privileges.