CVE-2026-46770: Medium severity Oracle Oracle Application Development Framework (ADF) vulnerability
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Development Framework (ADF), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Development Framework (ADF) accessible data as well as unauthorized read access to a subset of Oracle Application Development Framework (ADF) accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable HTTP access to ADF where possible. If HTTP access is required, configure the application server/network to restrict access to only trusted IP ranges or internal networks.
Oracle Application Development Framework (ADF) HTTP access = disable or restrict to trusted networks - Compensating control
Restrict access to ADF HTTP endpoints at the network perimeter (firewall/ACL) to trusted IPs and/or place ADF behind a VPN. Deploy a web application firewall (WAF) to detect and block exploitation attempts against ADF.
- Operational
Audit application and database logs for signs of unauthorized read, insert, update, or delete activity affecting ADF-accessible data; investigate and remediate any confirmed unauthorized changes and follow incident response procedures.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46770?
The severity of CVE-2026-46770 is rated as medium with a score of 6.1.
How do I fix CVE-2026-46770?
To fix CVE-2026-46770, it is recommended to apply the latest security patches provided by Oracle for the affected versions.
Which versions are affected by CVE-2026-46770?
CVE-2026-46770 affects Oracle Application Development Framework versions 12.2.1.4.0 and 14.1.2.0.0.
What type of attack does CVE-2026-46770 allow?
CVE-2026-46770 allows an unauthenticated attacker with network access via HTTP to exploit the vulnerability.
What is the potential impact of CVE-2026-46770?
The potential impact of CVE-2026-46770 includes unauthorized access to sensitive data due to its exploitability.