CVE-2026-83039
moderateAuthenticated Full Takeover of Oracle WebCenter Portal via Composer Flaw (CVSS 9.9)
Oracle WebCenter Portal (Fusion Middleware), specifically its Composer component, contains an easily exploitable flaw in versions 12.2.1.4.0 and 14.1.2.0.0 that lets a low-privileged authenticated attacker with HTTP network access take over the portal. The CVSS 3.1 base score is 9.9 (critical) with a scope change (S:C), meaning successful attacks on WebCenter Portal can significantly impact additional products beyond the vulnerable component. Successful exploitation yields full compromise of confidentiality, integrity, and availability of the affected installation. Any organization running the two affected WebCenter Portal releases and exposing them to users over the network is at risk, particularly portals reachable from untrusted or broad internal networks. The flaw is not in the CISA Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and no exploitation in the wild has been reported to date.
What to do: Apply the Oracle Critical Patch Update remediation for WebCenter Portal to both 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available, prioritizing any instance reachable from the internet or large internal user populations. Until patched, restrict network access to the Composer component, review low-privileged portal accounts for compromise or over-broad entitlements, and monitor authentication and Composer activity logs for anomalous behavior. Also assess adjacent Fusion Middleware products for follow-on impact given the documented scope change.
| Oracle WebCenter Portal (Oracle Fusion Middleware, Composer component) | 12.2.1.4.0 |
| Oracle WebCenter Portal (Oracle Fusion Middleware, Composer component) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.