ZeroHour

CVE-2026-83048

niche

Authenticated Data Exposure in Oracle WebCenter Portal Runtime Tools

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83048 is a vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting supported versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, allowing them to compromise Oracle WebCenter Portal. Because the vulnerability has a scope change (S:C), successful attacks may significantly impact additional products beyond WebCenter Portal itself, and can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. The impact is confidentiality-only per the CVSS vector (no integrity or availability impact), with a high CVSS 3.1 base score of 7.7. No public proof of concept is known, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83048 to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 installations. Restrict network/HTTP access to Runtime Tools endpoints and portal admin surfaces, and enforce least-privilege role assignments since exploitation requires only a low-privileged account. Review logs for authenticated users accessing data outside their expected authorization scope, and inventory any additional products integrated with WebCenter Portal that could be affected by the scope change.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, component: Runtime Tools)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
nichelikely low thousands of enterprise deployments worldwide, with only a subset internet-exposed — WebCenter Portal is on-premises enterprise middleware rather than a mass-market product, and public internet scans typically show only hundreds to a few thousand exposed Oracle WebCenter hosts; no active-install counts are available in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.