ZeroHour

CVE-2026-83049

niche

Authenticated Data-Access Flaw in Oracle WebCenter Portal Security Framework

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

A flaw in the Security Framework component of Oracle WebCenter Portal (part of Oracle Fusion Middleware) allows a low-privileged, authenticated remote attacker with HTTP network access to easily compromise the portal. Successful exploitation can yield unauthorized read access to critical data — up to complete access to all Oracle WebCenter Portal-accessible data — plus unauthorized update, insert, or delete access to some of that data. Because the vulnerability carries a scope change (CVSS 3.1 base score 8.5, vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N), successful attacks may significantly impact additional products beyond WebCenter Portal itself. Affected deployments are those running WebCenter Portal 12.2.1.4.0 or 14.1.2.0.0. There is no known public proof of concept and no evidence of in-the-wild exploitation; the CVE is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-83049 to affected WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 deployments as soon as the fixed release is available. Because exploitation requires only a low-privileged HTTP login, restrict portal access to trusted networks or VPN, enforce least-privilege accounts, and audit low-privilege user activity for anomalous reads or data modifications. Also review integrated systems reachable from the portal, since the scope change means successful attacks can impact additional products.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, Security Framework component)
Estimated exposure
nichelow thousands of enterprise deployments worldwide, with the internet-exposed subset likely well under 1,000 instances (rough estimate) — Oracle WebCenter Portal is a niche enterprise portal product typically deployed on internal networks, and public internet scan services historically show only a few hundred to low thousands of exposed Oracle WebCenter/Fusion Middleware…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.