ZeroHour

CVE-2026-83050

niche

Authenticated Unauthorized Data Access in Oracle WebCenter Portal Runtime Tools

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83050 is an easily exploitable vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker with only low-privileged (authenticated) access to the portal over HTTP can exploit the flaw to gain unauthorized read access to critical data — potentially all Oracle WebCenter Portal accessible data — as well as unauthorized update, insert, or delete access to some of that data. The vulnerability is scored 7.1 (high) with CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N, meaning no user interaction is required and confidentiality impact is high, though availability is not affected. Organizations running the affected WebCenter Portal versions with HTTP-reachable instances and low-privilege accounts (including self-registered or default portal users) are at risk of data theft and tampering. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation in the wild is not currently evidenced.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83050 to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 deployments. Restrict HTTP access to the portal so it is not reachable by untrusted or low-privilege users, and review portal account provisioning to minimize low-privileged accounts. Audit logs for unusual data reads or updates by low-privilege users to detect any attempted exploitation.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware)12.2.1.4.0
Oracle WebCenter Portal (Oracle Fusion Middleware)14.1.2.0.0
Estimated exposure
nichelikely hundreds to low thousands of internet-reachable instances (estimate) — Oracle WebCenter Portal is an enterprise portal product deployed primarily by large organizations, typically on-premises and often behind firewalls, so public scan data generally shows only a small number of internet-exposed instances…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.