Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-83039 2026-09-15

CVE-2026-83039: Critical Oracle WebCenter Portal Takeover Flaw Carries a Vendor-Assigned 9.9

"Oracle has disclosed a critical vulnerability in the Composer component of Oracle WebCenter Portal that lets a low-privileged attacker with network access take over the product entirely; and, per Oracle, may…"

Oracle has disclosed a critical vulnerability in the Composer component of Oracle WebCenter Portal that lets a low-privileged attacker with network access take over the product entirely; and, per Oracle, may significantly impact additional products beyond it.

What Is It

CVE-2026-83039 is a vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware, specifically in the Composer component. Oracle describes it as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks result in full takeover of the product.

The CVSS 3.1 base score currently associated with the CVE is 9.9 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, low privileges required, no user interaction, and a changed scope with high impact to confidentiality, integrity, and availability. This score is as-submitted rather than settled: the NVD record is still in Received status, so no NVD analyst has reviewed or confirmed the metrics, and the final published score and vector may differ.

Why It Matters

The combination that drives the 9.9 score is what makes this dangerous in practice: no user interaction, low complexity, and only a low-privileged account needed. Any authenticated portal user, including low-tier accounts that are frequently handed out broadly in enterprise portal deployments, is positioned to exploit it over HTTP. That reasoning holds on the severity metrics as currently reported; if NVD analysis revises them, the risk picture should be revisited.

The scope change is the second half of the problem. Oracle's wording is that, while the vulnerability lives in WebCenter Portal, "attacks may significantly impact additional products." That is a statement of possibility rather than a guarantee, but it is the reason the CVSS scope flag is set to Changed, and it means a compromise cannot be assumed to stay contained to the portal; it should be treated as a potential pivot into the broader Fusion Middleware environment.

There is no CISA KEV entry for this CVE in the supplied data, so active exploitation is not confirmed at this time.

What's Vulnerable

Patch Status

The CVE record carries a publication date of 2026-09-15 with NVD status Received, meaning NVD analysis is still pending. Note that Oracle ships Fusion Middleware security fixes only through its quarterly Critical Patch Update, released in January, April, July, and October; there is no September CPU, so the September date reflects the CVE record rather than an Oracle patch release, and the quarterly CPU that actually carries this fix should be confirmed directly with Oracle.

The Oracle advisory URL supplied with this record does not resolve to a valid Oracle advisory: the path cspusep2026.html is malformed and does not match Oracle's cpu<month><year> naming scheme for Critical Patch Update advisories. It should not be treated as the authoritative vendor reference. Administrators running either affected version should instead navigate to Oracle's security alerts index directly, identify the applicable Critical Patch Update advisory, and apply the corresponding fix. No specific CISA-mandated remediation deadline applies, as the CVE is not present in the supplied KEV data.

Sources