CVE-2026-60348: Medium severity Oracle Oracle JDeveloper vulnerability
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60348?
The severity of CVE-2026-60348 is rated as medium with a CVSS score of 5.9.
How do I fix CVE-2026-60348?
To fix CVE-2026-60348, users should upgrade to the latest patched version of Oracle JDeveloper.
Who is affected by CVE-2026-60348?
CVE-2026-60348 affects users of Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0.
What kind of attack does CVE-2026-60348 allow?
CVE-2026-60348 allows an unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.
Is there a workaround for CVE-2026-60348?
Currently, no specific workaround is provided for CVE-2026-60348; upgrading to the fixed version is recommended.