Junglewise Threat Intelligence

CVE-2026-83052: Oracle WebCenter Portal privilege escalation in Runtime Tools

CVE-2026-83052 · Severity: high · CVSS 7.6 · Published 2026-09-15

Executive brief

Oracle WebCenter Portal is an enterprise collaboration and content management platform used within Oracle Fusion Middleware. An authentication bypass vulnerability in the Runtime Tools component allows a high-privilege attacker with network access to gain unauthorized access to sensitive data and modify critical information stored in WebCenter Portal. The vulnerability also affects other connected Oracle products that rely on WebCenter Portal integration.

Technical details

This is a privilege escalation vulnerability in the Runtime Tools component of Oracle WebCenter Portal affecting versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is easily exploitable and can be triggered remotely via HTTP by an attacker with high-level credentials. Successful exploitation results in confidentiality breaches (unauthorized access to critical data) and integrity compromise (unauthorized modification, insertion, or deletion of data). The scope of impact extends beyond WebCenter Portal itself to other connected Oracle products, as noted by the CVSS scope change indicator. No known public exploits in the wild have been reported.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats