ZeroHour

CVE-2026-83047

niche

Unauthenticated Data Access Flaw in Oracle WebCenter Portal Runtime Tools

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83047 is a high-severity vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack can result in unauthorized access to critical data or complete read access to all Oracle WebCenter Portal accessible data, as well as unauthorized update, insert, or delete access to some of that data. Organizations running the affected on-premises or cloud deployments of WebCenter Portal are at risk, particularly any instance reachable from untrusted networks. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83047 to WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available for your release. Restrict HTTP access to WebCenter Portal Runtime Tools endpoints so they are reachable only from trusted internal networks or via VPN, and place the portal behind an authenticating reverse proxy where feasible. Review access and application logs for unauthenticated requests to Runtime Tools paths to rule out prior probing or data access.

Affected
Oracle WebCenter Portal (Fusion Middleware, component: Runtime Tools)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
nichelikely hundreds to low thousands of internet-exposed instances out of a modest global installed base of enterprise deployments (order of magnitude: thousands… — WebCenter Portal is enterprise middleware typically deployed internally within mid-to-large organizations, and public internet scan data for Oracle WebCenter/WebLogic-family endpoints generally shows only low thousands of directly exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.