CVE-2026-83064
moderateAuthenticated Takeover Vulnerability in Oracle WebCenter Portal Runtime Tools
CVE-2026-83064 is a critical (CVSS 9.1) flaw in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker with network access via HTTP and already-high privileges can exploit it easily to fully compromise the WebCenter Portal deployment, and because the vulnerability changes scope, successful attacks may also significantly impact additional products beyond the portal itself. The impact is total compromise of confidentiality, integrity, and availability, effectively a takeover of the affected installation. Organizations running either affected version in internet-reachable or broadly accessible deployments are at risk, though exploitation requires valid high-privileged credentials. No public proof-of-concept exists and the vulnerability is not on the CISA Known Exploited Vulnerabilities list, so no active exploitation is known.
What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83064 to all WebCenter Portal installations running 12.2.1.4.0 or 14.1.2.0.0. Restrict network access to Runtime Tools and administrative HTTP endpoints so only trusted administrators and networks can reach them, and audit high-privileged accounts for signs of misuse. Review HTTP access logs for anomalous requests from privileged accounts targeting Runtime Tools endpoints.
| Oracle WebCenter Portal (Oracle Fusion Middleware, Runtime Tools component) | 12.2.1.4.0 |
| Oracle WebCenter Portal (Oracle Fusion Middleware, Runtime Tools component) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.