---
id: CVE-2026-83065
title: >-
  Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion
  Middleware (component: Runtime Tools)
summary: >-
  Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion
  Middleware (component: Runtime Tools).   The supported version that is
  affected is 14.1.2.0.0. Difficult to exploit vulnerability allows
  unauthenticated attacker with …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: Oracle Corporation
product: Oracle WebCenter Portal
affected:
  - oracle_webcenter_portal 14.1.2.0.0
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T16:17:53.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-83065'
references:
  - url: 'https://www.oracle.com/security-alerts/cspusep2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T14:57:07.918527Z'
epss: 0.00235
epssPercentile: 0.14714
ingestedAt: '2026-09-15T20:44:02.444Z'
---

## Overview

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).   The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Portal executes to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
