ZeroHour

CVE-2026-83052

moderate

Privileged Data Access Flaw in Oracle WebCenter Portal Runtime Tools

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83052 is an easily exploitable vulnerability in the Runtime Tools component of Oracle WebCenter Portal (part of Oracle Fusion Middleware) affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is triggered remotely by a high-privileged attacker who has network access to the portal over HTTP, and because the flaw changes scope, a successful attack can significantly impact products beyond WebCenter Portal itself. A successful exploitation yields unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data, as well as unauthorized update, insert, or delete access to some of that data, with no availability impact (CVSS 3.1 base score 7.6, high). Organizations running the affected WebCenter Portal versions with admin/runtime tooling reachable over the network are exposed. The issue is not listed in CISA's KEV catalog, no public proof of concept is known, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83052 to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 deployments as soon as it is available. Restrict HTTP access to WebCenter Portal and its Runtime Tools/admin interfaces to trusted management networks or VPN, and enforce least-privilege on portal administrator accounts. Review portal audit logs for anomalous data reads or unauthorized inserts/updates/deletes by high-privileged accounts, and rotate credentials for those accounts if compromise is suspected.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, component: Runtime Tools)
Estimated exposure
moderate≈ low thousands of enterprise deployments, with only a small fraction of portal/admin endpoints internet-exposed — WebCenter Portal is on-premises enterprise middleware rather than a mass-market product; public internet scan data typically shows only a few thousand reachable WebCenter endpoints worldwide, and no official install counts exist — clearly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.