Junglewise Threat Intelligence

CVE-2026-83041: Oracle WebCenter Portal unauthorized data access in Portlet Services

CVE-2026-83041 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle WebCenter Portal. Vendors: Oracle.

Executive brief

Oracle WebCenter Portal is a component of Oracle Fusion Middleware used to build enterprise portals and collaboration applications. A vulnerability in its Portlet Services component allows a low-privileged attacker to gain unauthorized access to sensitive data through network-based attacks. Successful exploitation could result in exposure of critical business information stored within the portal and related systems.

Technical details

This is an authorization bypass vulnerability in the Portlet Services component of Oracle WebCenter Portal. The vulnerability is easily exploitable and requires only low-privilege network access over HTTP, with no user interaction needed. An authenticated attacker can leverage this flaw to access data they should not be authorized to view, potentially affecting confidentiality across multiple Oracle products due to a scope change. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0; patch availability through Oracle's standard security updates is expected.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats