Junglewise Threat Intelligence

CVE-2026-83346: Oracle Fusion Middleware Control cross-site vulnerability in Framework

CVE-2026-83346 · Severity: medium · CVSS 5.4 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Fusion Middleware Control is a web-based management interface for Oracle's integration platform. A vulnerability in its Framework component allows a low-privileged network attacker to read, modify, or delete sensitive data by tricking an authorized user into performing an action. The attack succeeds via the web interface and can impact other connected systems due to the product's scope within the middleware environment.

Technical details

This is a cross-site attack vulnerability in the Framework component of Oracle Fusion Middleware Control, exploitable over the network via HTTP by an attacker with low privilege credentials. The vulnerability requires user interaction (user-assisted exploitation) and operates with a changed security scope, meaning the impact extends beyond the direct component to other systems. An attacker can achieve unauthorized read, insert, update, and delete operations on accessible data. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Patch availability should be checked via Oracle's security advisories.

Affected products

  • Oracle Fusion Middleware Control 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats