CVE-2026-83053
moderateAuthenticated Takeover Flaw in Oracle WebCenter Portal Runtime Tools
A high-severity (CVSS 8.8) vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows a low-privileged authenticated attacker with network access via HTTP to fully compromise the WebCenter Portal instance. The flaw is rated as easily exploitable, requiring only low privileges, no user interaction, and no special conditions, and successful attacks impact confidentiality, integrity, and availability — effectively a complete takeover of the portal. Affected deployments are Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 running within Oracle Fusion Middleware environments. The affected versions are supported, so patches should be available through Oracle's regular Critical Patch Update process. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known at this time.
What to do: Apply the Oracle Critical Patch Update that remediates this issue for WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available. In the interim, restrict network access to WebCenter Portal and Runtime Tools endpoints (VPN/IP allowlisting rather than open HTTP exposure), audit low-privileged portal accounts for abuse or unexpected privilege changes, and monitor logs for authenticated users accessing Runtime Tools functionality outside normal behavior.
| Oracle WebCenter Portal (Oracle Fusion Middleware, component: Runtime Tools) | 12.2.1.4.0 |
| Oracle WebCenter Portal (Oracle Fusion Middleware, component: Runtime Tools) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.