Junglewise Threat Intelligence

CVE-2026-83050: Oracle WebCenter Portal authentication bypass in Runtime Tools

CVE-2026-83050 · Severity: high · CVSS 7.1 · Published 2026-09-15

Executive brief

Oracle WebCenter Portal is a content management and collaboration platform used within Oracle Fusion Middleware deployments. A vulnerability in the Runtime Tools component allows authenticated attackers with network access to read sensitive data and make unauthorized modifications to portal content, potentially exposing customer information and enabling operational disruption.

Technical details

This is an easily exploitable authentication/authorization weakness in the Oracle WebCenter Portal Runtime Tools component, requiring low privileges and network-reachable HTTP access. The vulnerability allows an authenticated attacker to bypass authorization controls and gain unauthorized read and write access to portal data. Successful exploitation results in confidentiality and integrity compromise (CVSS 3.1 score 7.1). The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. Patches are expected from Oracle as part of their standard security release cycle.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats