Junglewise Threat Intelligence

CVE-2026-83046: Oracle WebCenter Portal privilege escalation in Runtime Tools

CVE-2026-83046 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle WebCenter Portal. Vendors: Oracle.

Executive brief

Oracle WebCenter Portal is a web-based enterprise content and collaboration platform used to manage and share business information. This vulnerability allows authenticated users with low-level network access to bypass security controls and gain unauthorized access to sensitive data or disrupt service availability. Exploitation requires no user interaction and could expose customer data or degrade portal operations.

Technical details

A privilege escalation vulnerability exists in the Runtime Tools component of Oracle WebCenter Portal that allows low-privileged attackers with network access to compromise the portal. The vulnerability is easily exploitable via HTTP and requires low-level authentication privileges but no user interaction. Successful exploitation can result in unauthorized access to critical confidential data and partial denial of service of the portal. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0; patches or workarounds should be available from Oracle's security advisories.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed: Published in Oracle Critical Patch Update

References

Related threats