Junglewise Threat Intelligence

CVE-2026-83265: Oracle Web Services Manager unauthenticated data access in Web Services Agent

CVE-2026-83265 · Severity: high · CVSS 8.2 · Published 2026-09-15

Technologies: Oracle Web Services Manager. Vendors: Oracle.

Executive brief

Oracle Web Services Manager is a middleware component used to manage and secure web services in enterprise environments. An unauthenticated attacker can exploit this vulnerability remotely over HTTP to gain unauthorized access to sensitive data or modify critical information within the system, potentially exposing customer data and enabling unauthorized changes to business-critical web service configurations.

Technical details

This is an unauthenticated remote vulnerability in the Web Services Agent component of Oracle Web Services Manager (versions 12.2.1.4.0 and 14.1.2.0.0). The vulnerability allows network-based attackers without credentials to access the service via HTTP and gain unauthorized read and partial write access to sensitive data. No user interaction or elevated privileges are required to exploit this flaw. Successful exploitation results in confidentiality and integrity violations through unauthorized data access and modification. Patch availability has not been confirmed from the advisory text.

Affected products

  • Oracle Web Services Manager 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats