Junglewise Threat Intelligence

CVE-2026-83064: Oracle WebCenter Portal privilege escalation in Runtime Tools

CVE-2026-83064 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Oracle WebCenter Portal is a portal application used within the Oracle Fusion Middleware suite to deliver enterprise content and collaboration features. A vulnerability in the Runtime Tools component allows an authenticated high-privileged attacker with network access to achieve complete control over the portal system and potentially impact other connected systems. This could result in unauthorized access to sensitive enterprise data, service disruption, or lateral movement to other infrastructure.

Technical details

The vulnerability is an easily exploitable flaw in Oracle WebCenter Portal's Runtime Tools component that requires high-level privileges and network access via HTTP to trigger. It allows an authenticated high-privileged attacker to compromise the portal, with scope change indicating that successful exploitation may impact additional products beyond WebCenter Portal itself. The attack requires no user interaction and results in complete system takeover, including confidentiality, integrity, and availability compromise. Patches are expected to be available through Oracle's standard security update process.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats