CVE-2026-83065
nicheUnauthenticated Adjacent-Network Takeover in Oracle WebCenter Portal 14.1.2.0.0
CVE-2026-83065 is a difficult-to-exploit vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting only version 14.1.2.0.0. It allows an unauthenticated attacker who is on the same physical communication segment (adjacent network) as the server running WebCenter Portal to fully compromise the application, with high impact on confidentiality, integrity, and availability — effectively a complete takeover of the portal. Exploitation requires high attack complexity and network adjacency, so the realistic threat is from insiders or attackers who already have a foothold on the internal LAN/VLAN where the portal host resides. Any organization running Oracle WebCenter Portal 14.1.2.0.0 is affected; prior versions are not listed as affected. There is no known public proof of concept, it is not in the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-83065 and move off the affected 14.1.2.0.0 release to the patched build referenced in Oracle's advisory. Restrict and segment network access to WebCenter Portal hosts so that only required management and application traffic can reach the server's physical network segment. Review portal logs for unauthorized configuration changes or new administrative accounts, since successful attacks result in full application takeover.
| Oracle WebCenter Portal (Oracle Fusion Middleware, component: Runtime Tools) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Portal executes to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.