CVE-2026-61061: High severity Oracle Oracle JDeveloper vulnerability
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle JDeveloper (Oracle Fusion Middleware) - Security Frameworkto a version that resolves this vulnerability.Fixed in 12.2.1.4.0 - Upgrade
Upgrade
Oracle JDeveloper (Oracle Fusion Middleware) - Security Frameworkto a version that resolves this vulnerability.Fixed in 14.1.2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61061?
CVE-2026-61061 has a high severity rating of 7.
How do I fix CVE-2026-61061?
To address CVE-2026-61061, update to the latest version of Oracle JDeveloper that is not affected.
What types of systems are affected by CVE-2026-61061?
CVE-2026-61061 affects Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0.
Who can exploit CVE-2026-61061?
CVE-2026-61061 can be exploited by a low privileged attacker with logon access to the infrastructure.
What components of Oracle are impacted by CVE-2026-61061?
CVE-2026-61061 impacts the Security Framework component of the Oracle JDeveloper product.