CVE-2026-60350: Infoleak
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper. While the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60350?
The severity of CVE-2026-60350 is medium with a CVSS score of 6.5.
How do I fix CVE-2026-60350?
To fix CVE-2026-60350, you should update to the latest supported version of Oracle JDeveloper.
Which versions of Oracle JDeveloper are affected by CVE-2026-60350?
The affected versions of Oracle JDeveloper are 12.2.1.4.0 and 14.1.2.0.0.
Can CVE-2026-60350 be exploited remotely?
No, CVE-2026-60350 requires local access to the infrastructure where Oracle JDeveloper is executed.
What type of attack does CVE-2026-60350 facilitate?
CVE-2026-60350 facilitates an information leak by a low privileged attacker.