CVE-2026-83043
moderateUnauthenticated CSRF-Style Takeover Flaw in Oracle WebCenter Portal Composer
CVE-2026-83043 is a critical (CVSS 9.6) flaw in the Composer component of Oracle WebCenter Portal, affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated remote attacker can exploit it over HTTP, but successful attacks require a victim (someone other than the attacker) to interact with a crafted request — a pattern consistent with cross-site request forgery or similar victim-triggered web exploitation. A successful attack results in complete takeover of Oracle WebCenter Portal, and because the vulnerability changes scope, the impact can extend significantly beyond the portal itself to additional products in the environment. Organizations running either affected version on internet-facing or broadly reachable networks are exposed to full compromise of confidentiality, integrity, and availability of the portal. No public proof-of-concept exists and the issue is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83043 to WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available for your environment. In the interim, restrict HTTP access to the portal and Composer surfaces (VPN/IP allowlisting, WAF rules), enforce SameSite cookie attributes and other CSRF mitigations, and train users not to interact with unsolicited links while authenticated. Review portal logs for unexpected account, privilege, or content changes that could indicate an attempted or successful takeover.
| Oracle WebCenter Portal (Oracle Fusion Middleware, Composer component) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.