CVE-2026-35243

7.8

Oracle · Application Development Framework

A vulnerability in the Oracle ADF Faces component allows a low privileged attacker with local infrastructure access to achieve full system takeover.

Executive summary

A critical vulnerability in Oracle Application Development Framework (ADF) allows authenticated, low privileged attackers to gain complete control over the affected infrastructure.

Vulnerability

This is an easily exploitable vulnerability within the ADF Faces component that permits an attacker with low privileges and local access to the underlying infrastructure to compromise the application. The flaw allows for a complete takeover of the framework, impacting confidentiality, integrity, and availability.

Business impact

The potential for a full takeover of the Oracle Application Development Framework poses a severe risk to organizational operations. A successful exploit grants an attacker the ability to manipulate data, exfiltrate sensitive information, or disrupt critical business services. Given the CVSS score of 7.8, this vulnerability represents a high-risk security gap that requires immediate attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Apply the security patches provided in the April 2026 Oracle Critical Patch Update located at the official Oracle security advisory page.

Proactive Monitoring: Monitor server access logs for unusual command execution patterns or unauthorized attempts to escalate privileges within the ADF infrastructure.

Compensating Controls: Ensure that access to the infrastructure hosting the ADF is strictly restricted to authorized personnel only, utilizing the principle of least privilege to limit the exposure of local accounts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Oracle ADF versions 12.2.1.4.0 or 14.1.2.0.0 must prioritize the application of the latest vendor security updates. Given the capability for total system takeover, delaying remediation increases the risk of persistent unauthorized access. Security teams should verify that all affected instances are identified and patched in accordance with Oracle's official guidance.

More Oracle CVEs

Sources