CVE-2026-83047
nicheUnauthenticated Data Access Flaw in Oracle WebCenter Portal Runtime Tools
CVE-2026-83047 is a high-severity vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack can result in unauthorized access to critical data or complete read access to all Oracle WebCenter Portal accessible data, as well as unauthorized update, insert, or delete access to some of that data. Organizations running the affected on-premises or cloud deployments of WebCenter Portal are at risk, particularly any instance reachable from untrusted networks. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83047 to WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available for your release. Restrict HTTP access to WebCenter Portal Runtime Tools endpoints so they are reachable only from trusted internal networks or via VPN, and place the portal behind an authenticating reverse proxy where feasible. Review access and application logs for unauthenticated requests to Runtime Tools paths to rule out prior probing or data access.
| Oracle WebCenter Portal (Fusion Middleware, component: Runtime Tools) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.