Vulnerability in Oracle Application Development Framework ADF Faces by Oracle
CVE-2026-46772

4.7MEDIUM

What is CVE-2026-46772?

A vulnerability exists within the Oracle Application Development Framework (ADF) component in Oracle Fusion Middleware, specifically in ADF Faces. This vulnerability could be exploited by a high-privileged attacker who has already logged on to the infrastructure where ADF operates. The attacker could gain unauthorized access to sensitive data or manipulate data, including the ability to update, insert, or delete records accessible by ADF. Supported versions affected include 12.2.1.4.0 and 14.1.2.0.0, underscoring the importance of addressing this security issue to protect critical data.

Affected Version(s)

Oracle Application Development Framework (ADF) 12.2.1.4.0

Oracle Application Development Framework (ADF) 14.1.2.0.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.