CVE-2026-83265
moderateUnauthenticated data-access flaw in Oracle Web Services Manager (Web Services Agent)
Oracle Web Services Manager (OWSM), a component of Oracle Fusion Middleware, contains an easily exploitable flaw in its Web Services Agent that allows an unauthenticated attacker with network access via HTTP to compromise the product. The vulnerability requires no privileges or user interaction and has low attack complexity, meaning a remote attacker who can reach an OWSM endpoint over HTTP can exploit it directly. A successful attack can result in unauthorized read access to critical data — up to complete access to all OWSM-accessible data — as well as unauthorized update, insert, or delete access to some of that data; availability is not impacted (CVSS 3.1 base score 8.2). Organizations running OWSM versions 12.2.1.4.0 or 14.1.2.0.0 are affected. No public proof of concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remedies this flaw to all OWSM 12.2.1.4.0 and 14.1.2.0.0 installations. Restrict network access so OWSM/Web Services Agent endpoints are not reachable by untrusted networks or anonymous HTTP clients. Review OWSM and WebLogic access logs for unauthenticated HTTP requests to agent endpoints and investigate any unexpected data access or modification.
| Oracle Web Services Manager (Oracle Fusion Middleware, component: Web Services Agent) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Agent). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Web Services Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.