CVE-2026-83045
moderateAuthenticated Critical Data Access Flaw in Oracle WebCenter Portal Runtime Tools
Oracle WebCenter Portal (part of Oracle Fusion Middleware), specifically the Runtime Tools component, contains an easily exploitable vulnerability in versions 12.2.1.4.0 and 14.1.2.0.0 that allows a low-privileged (authenticated) attacker with network access via HTTP to compromise the product with no user interaction. A successful attack yields unauthorized read access to critical data or complete access to all Oracle WebCenter Portal accessible data, plus unauthorized update, insert, or delete access to some of that data (high confidentiality impact, low integrity impact, no availability impact). The CVSS 3.1 base score is 8.5 with a scope change, meaning successful attacks may also significantly impact additional products beyond WebCenter Portal itself. Affected organizations are enterprises running the two listed on-premises WebCenter Portal versions. There is no known public proof of concept, the flaw is not in the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83045 to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 installations as soon as possible. Inventory your estate for these exact versions, restrict HTTP access to WebCenter Portal to trusted networks and VPN, and review least-privilege settings on low-privileged portal accounts. Because the vulnerability carries a scope change, also audit data accessible from integrated systems and check logs for anomalous authenticated read or data-modification activity.
| Oracle WebCenter Portal (Oracle Fusion Middleware, Runtime Tools component) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.