PT-2026-34160 · Oracle · Oracle Application Development Framework+1

Published

2026-04-21

·

Updated

2026-04-26

·

CVE-2026-35243

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Application Development Framework (ADF) versions 12.2.1.4.0 Oracle Application Development Framework (ADF) versions 14.1.2.0.0
Description An issue exists in the ADF Faces component of the Oracle Application Development Framework (ADF) within Oracle Fusion Middleware. A low-privileged attacker with access to the infrastructure where the framework executes can exploit this flaw to compromise the system, potentially leading to a full takeover of the Oracle Application Development Framework (ADF).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-35243

Affected Products

Oracle Application Development Framework
Application Development Framework