CVE-2026-83040
moderateUnauthenticated SOAP-Triggered Takeover in Oracle WebCenter Portal (Portlet Services)
A critical vulnerability (CVSS 9.6) in the Portlet Services component of Oracle WebCenter Portal allows an unauthenticated remote attacker with network access via SOAP to fully compromise the portal, including complete takeover of confidentiality, integrity, and availability. Exploitation is rated as easy but requires human interaction from a victim other than the attacker, suggesting a cross-site request forgery–style pattern in which a tricked user's session or browser action is needed to complete the attack. The scope is changed, meaning a successful attack on WebCenter Portal can also significantly impact additional products in the surrounding Fusion Middleware environment. Only Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 are listed as affected. No public proof of concept is known and the flaw is not on the CISA KEV, indicating no confirmed exploitation in the wild to date.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83040 to both WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as soon as the quarterly CPU is available. In the interim, restrict or authenticate access to SOAP and portlet service endpoints at the network layer (WAF/reverse proxy rules, IP allow-listing) and avoid exposing the portal SOAP stack to the public internet. Because successful attacks require human interaction, reinforce anti-CSRF and session hygiene, and review logs for unauthenticated SOAP traffic against Portlet Services endpoints as an indicator of targeting.
| Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component) | 12.2.1.4.0 |
| Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.