HIGH 7.2

CVE-2026-46769: Oracle ADF Access Control Vulnerability (CVSS 7.2)

Oracle's Application Development Framework (ADF), a middleware component used to build enterprise applications, contains a security vulnerability that allows administrators or other high-privileged users with network access to gain complete control over affected systems. An attacker with these elevated privileges can read, modify, or delete sensitive data and disrupt operations. The vulnerability affects two specific versions: 12.2.1.4.0 and 14.1.2.0.0.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-284
Affected products
2 configuration(s)
Published / Modified
2026-06-17 / 2026-06-19

NVD description (verbatim)

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-46769 is an improper access control vulnerability (CWE-284) in Oracle ADF Shared Components. The flaw permits high-privileged attackers to bypass authorization controls via HTTP requests, resulting in unauthorized access to the framework's confidentiality, integrity, and availability guarantees. The attack vector is network-based with low attack complexity, requiring only administrative credentials. The vulnerability does not involve user interaction or cross-system boundary crossing, indicating direct compromise of the targeted ADF instance.

Business impact

Organizations using Oracle ADF in production environments face risk of unauthorized administrative actions, data theft, system tampering, and service disruption. The threat is most acute in deployments where ADF hosts customer-facing applications or sensitive business processes. Compromise could expose customer data, disrupt transaction processing, or enable fraudulent modifications to application logic. Remediation delays compound risk in shared infrastructure scenarios where multiple business units depend on affected ADF instances.

Affected systems

This vulnerability specifically targets Oracle Application Development Framework versions 12.2.1.4.0 and 14.1.2.0.0. Any organization running Fusion Middleware with these ADF versions should assess their deployment scope. Versions outside this range may not be affected; consult Oracle's official security documentation to confirm patch status and version eligibility. Both versions remain in Oracle's support lifecycle, making patching a reasonable expectation.

Exploitability

Exploitation requires high-privilege access—typically an administrator account or authenticated user with elevated role permissions. While the attack complexity is low once privileges are obtained, the prerequisite of high-level credentials significantly limits opportunistic exploitation. External threat actors would first need to compromise a privileged account through phishing, credential theft, or other means before leveraging this flaw. Insider threats or compromised service accounts pose the more immediate risk profile.

Remediation

Oracle has released security patches addressing this vulnerability. Organizations should verify applicable patch versions through Oracle's Critical Patch Updates (CPU) or Security Alert documentation. Testing patches in non-production environments before deployment is essential to avoid application disruption. For environments where immediate patching is infeasible, implement network-level controls restricting administrative access to ADF instances and audit logs for suspicious privileged user activity.

Patch guidance

Consult Oracle's official Critical Patch Update advisories for the exact patch versions applicable to your ADF 12.2.1.4.0 or 14.1.2.0.0 deployment. Apply patches in a staged manner: test in development, validate in staging, then deploy to production during a controlled maintenance window. Verify patch installation by confirming version numbers post-deployment and reviewing Oracle's patch verification procedures. Maintain documentation of patch dates and applied bundle versions for compliance and incident response purposes.

Detection guidance

Monitor HTTP traffic to ADF instances for unusual administrative API calls or privilege escalation patterns. Enable and review authentication and authorization logs within Fusion Middleware for failed or anomalous high-privilege operations. Implement alerts for unexpected configuration changes or privileged user actions outside normal business windows. Network-based intrusion detection signatures specific to ADF exploitation attempts may be available through your security vendor; coordinate with Oracle security teams to obtain indicators of compromise relevant to this CVE.

Why prioritize this

This vulnerability scores 7.2 (HIGH) on CVSS v3.1 due to its combination of network accessibility, low attack complexity, and severe impact across confidentiality, integrity, and availability. The limiting factor is the requirement for high-level privileges, which reduces the likelihood of mass exploitation from untrusted networks. Organizations should prioritize patching production ADF instances and any systems processing sensitive or regulated data. However, it is not classified for KEV (Known Exploited Vulnerability) status, suggesting active in-the-wild exploitation has not been publicly documented at time of publication.

Risk score, explained

The CVSS 3.1 score of 7.2 reflects a HIGH-severity issue due to full compromise potential (CIA impacts all rated as High) accessible over the network with minimal attack prerequisites. The score is tempered by the requirement for high-privilege authentication (PR:H), which narrows the attack surface. Organizations with mature identity governance and network segmentation can reduce realized risk significantly. However, the breadth of impact—if credentials are compromised—justifies rapid patching in most risk-conscious environments.

Frequently asked questions

Do I need to patch immediately if I run ADF 12.2.1.4.0 or 14.1.2.0.0?

Yes, if your systems are exposed to untrusted networks or you cannot rule out insider risk. Patching should occur during your next scheduled maintenance window, with priority given to production instances. If immediate patching is infeasible, implement compensating controls such as restricted network access and enhanced audit logging while you prepare a formal patch deployment.

Is this vulnerability currently being exploited in the wild?

As of the publication date, this vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating that active exploitation has not been publicly reported. However, absence from KEV does not guarantee absence of exploitation; monitor threat intelligence feeds and vendor advisories for updates.

What if I run a version of ADF other than 12.2.1.4.0 or 14.1.2.0.0?

Oracle's advisory specifically identifies these two versions as vulnerable. Other versions may not be affected, but verify your exact version number against Oracle's Security Alert document. Interim versions, patches, or Extended Support Release builds may have different vulnerability status.

Can network segmentation reduce my risk if I cannot patch immediately?

Yes. Restrict HTTP/HTTPS access to ADF instances to only trusted administrative networks, and require VPN or jump-host access. This significantly reduces the practical attack surface while you prepare and test patches. Combine network controls with comprehensive logging to detect anomalies and comply with your incident response requirements.

This analysis is provided for informational purposes and reflects the vulnerability details as published by Oracle and recorded in the CVE database. SEC.co does not distribute patches, vulnerability scanning tools, or exploit code. Organizations must verify patch applicability against their specific deployment configurations and consult Oracle's official Security Alerts and Critical Patch Update advisories before taking remediation actions. Patch versions, timelines, and mitigation strategies may vary based on Oracle support agreements and platform specifics. All security remediation actions carry inherent risk and must be validated in non-production environments before production deployment. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).