Oracle has disclosed a critical vulnerability in the Composer component of Oracle WebCenter Portal that lets a low-privileged attacker with network access take over the product entirely; and, per Oracle, may significantly impact additional products beyond it.
What Is It
CVE-2026-83039 is a vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware, specifically in the Composer component. Oracle describes it as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks result in full takeover of the product.
The CVSS 3.1 base score currently associated with the CVE is 9.9 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, low privileges required, no user interaction, and a changed scope with high impact to confidentiality, integrity, and availability. This score is as-submitted rather than settled: the NVD record is still in Received status, so no NVD analyst has reviewed or confirmed the metrics, and the final published score and vector may differ.
Why It Matters
The combination that drives the 9.9 score is what makes this dangerous in practice: no user interaction, low complexity, and only a low-privileged account needed. Any authenticated portal user, including low-tier accounts that are frequently handed out broadly in enterprise portal deployments, is positioned to exploit it over HTTP. That reasoning holds on the severity metrics as currently reported; if NVD analysis revises them, the risk picture should be revisited.
The scope change is the second half of the problem. Oracle's wording is that, while the vulnerability lives in WebCenter Portal, "attacks may significantly impact additional products." That is a statement of possibility rather than a guarantee, but it is the reason the CVSS scope flag is set to Changed, and it means a compromise cannot be assumed to stay contained to the portal; it should be treated as a potential pivot into the broader Fusion Middleware environment.
There is no CISA KEV entry for this CVE in the supplied data, so active exploitation is not confirmed at this time.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle WebCenter Portal (Oracle Fusion Middleware)
- Component: Composer
- Affected supported versions: 12.2.1.4.0 and 14.1.2.0.0
Patch Status
The CVE record carries a publication date of 2026-09-15 with NVD status Received, meaning NVD analysis is still pending. Note that Oracle ships Fusion Middleware security fixes only through its quarterly Critical Patch Update, released in January, April, July, and October; there is no September CPU, so the September date reflects the CVE record rather than an Oracle patch release, and the quarterly CPU that actually carries this fix should be confirmed directly with Oracle.
The Oracle advisory URL supplied with this record does not resolve to a valid Oracle advisory: the path cspusep2026.html is malformed and does not match Oracle's cpu<month><year> naming scheme for Critical Patch Update advisories. It should not be treated as the authoritative vendor reference. Administrators running either affected version should instead navigate to Oracle's security alerts index directly, identify the applicable Critical Patch Update advisory, and apply the corresponding fix. No specific CISA-mandated remediation deadline applies, as the CVE is not present in the supplied KEV data.
Sources
- Oracle Critical Patch Update Advisory (as supplied, unverified and likely invalid; the filename does not follow Oracle's
cpu<month><year>advisory URL scheme and should be replaced with the correct advisory located via Oracle's security alerts index), https://www.oracle.com/security-alerts/cspusep2026.html - NVD, CVE-2026-83039 (record in Received status; metrics not yet analyst-confirmed), https://nvd.nist.gov/vuln/detail/CVE-2026-83039