Junglewise Threat Intelligence

CVE-2026-83045: Oracle WebCenter Portal privilege escalation in Runtime Tools

CVE-2026-83045 · Severity: high · CVSS 8.5 · Published 2026-09-15

Technologies: Oracle WebCenter Portal. Vendors: Oracle.

Executive brief

Oracle WebCenter Portal is a portal platform used to build enterprise web applications and collaboration spaces. A vulnerability in the Runtime Tools component allows a low-privileged, authenticated network attacker to access and modify sensitive data or access additional backend systems. The flaw enables unauthorized data exposure and manipulation with potential cascading impacts across Oracle Fusion Middleware.

Technical details

The vulnerability is a privilege escalation flaw in the Runtime Tools component of Oracle WebCenter Portal. It requires network access via HTTP and low-level user privileges, but does not require user interaction. An authenticated attacker can exploit this to bypass authorization controls and read, modify, insert, or delete data within WebCenter Portal and potentially impact connected systems (scope change per CVSS). Affected versions are 12.2.1.4.0 and 14.1.2.0.0. Oracle has issued a security patch; consult the official security bulletin for remediation details.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats