Junglewise Threat Intelligence

CVE-2026-83051: Oracle WebCenter Portal unauthorized data access in Runtime Tools

CVE-2026-83051 · Severity: high · CVSS 7.5 · Published 2026-09-15

Executive brief

Oracle WebCenter Portal is a centralized platform for building enterprise web applications and managing digital content. An unauthenticated attacker can remotely access the Runtime Tools component without credentials, potentially exposing sensitive business data stored within the portal. This vulnerability allows attackers to view and exfiltrate confidential information accessible through the portal without needing a valid user account.

Technical details

The vulnerability exists in the Runtime Tools component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0) and is exploitable via HTTP without requiring authentication or user interaction. The exact root cause is not fully detailed in available sources, but the attack vector is network-based through HTTP requests to an accessible endpoint. Successful exploitation grants unauthenticated attackers unauthorized access to confidential data within the portal, with impact limited to confidentiality (no integrity or availability impact reported). Patch availability and mitigation steps should be checked against Oracle's security advisory CVE-2026-83051.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats