ZeroHour

CVE-2026-83045

moderate

Authenticated Critical Data Access Flaw in Oracle WebCenter Portal Runtime Tools

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

Oracle WebCenter Portal (part of Oracle Fusion Middleware), specifically the Runtime Tools component, contains an easily exploitable vulnerability in versions 12.2.1.4.0 and 14.1.2.0.0 that allows a low-privileged (authenticated) attacker with network access via HTTP to compromise the product with no user interaction. A successful attack yields unauthorized read access to critical data or complete access to all Oracle WebCenter Portal accessible data, plus unauthorized update, insert, or delete access to some of that data (high confidentiality impact, low integrity impact, no availability impact). The CVSS 3.1 base score is 8.5 with a scope change, meaning successful attacks may also significantly impact additional products beyond WebCenter Portal itself. Affected organizations are enterprises running the two listed on-premises WebCenter Portal versions. There is no known public proof of concept, the flaw is not in the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83045 to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 installations as soon as possible. Inventory your estate for these exact versions, restrict HTTP access to WebCenter Portal to trusted networks and VPN, and review least-privilege settings on low-privileged portal accounts. Because the vulnerability carries a scope change, also audit data accessible from integrated systems and check logs for anomalous authenticated read or data-modification activity.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, Runtime Tools component)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
moderatelikely low thousands of enterprise deployments worldwide, with only a small fraction internet-exposed — WebCenter Portal is a niche enterprise Java middleware product deployed on-premises by mid-size and large organizations, and public internet scans typically show only a small number of exposed WebCenter Portal instances, so total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.