Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows an attacker with low privileges but network access via HTTP to compromise the portal. Exploitation can lead to the attacker obtaining full control, resulting in a complete takeover of the portal. The CVSS vector reflects high impacts on confidentiality, integrity and availability, indicating that compromise can affect all core services and data.

Affected Systems

Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected – any installation of these releases is vulnerable if the Runtime Tools component is enabled.

Risk and Exploitability

The CVSS score of 8.8 denotes high severity. The EPSS score is less than 1 %, suggesting low immediate exploitation likelihood, but the existence of an HTTP‑exposed interface and the low privilege requirement means an attacker can reach the target from any connected network. This vulnerability is not listed in CISA’s KEV catalog, yet the impact of a successful exploit is significant, so the overall risk remains high for exposed or inadequately segmented environments.

Generated by OpenCVE AI on September 17, 2026 at 03:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle WebCenter Portal to a version that contains the fix for the Runtime Tools vulnerability or retarget the installation to a later release that no longer includes the affected component.
  • Restrict HTTP access to the portal by applying firewall rules or network segmentation so that only trusted internal hosts can reach the service.
  • If the Runtime Tools functionality is not required for business processes, disable or uninstall it to eliminate the attack surface.
  • Monitor HTTP traffic for anomalous requests that match known exploitation patterns and review logs for unauthorized changes to portal configuration or content.

Generated by OpenCVE AI on September 17, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Portal Remote Code Execution Vulnerability
Weaknesses CWE-200
CWE-284
CWE-78

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:07.255Z

Reserved: 2026-08-31T15:40:57.335Z

Link: CVE-2026-83053

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:13.890

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:00:20Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')