Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-83040 2026-09-15

CVE-2026-83040: Critical Oracle WebCenter Portal Flaw Allows Full Takeover via SOAP

"The editorial note you pasted is cut off mid-sentence ("is admitted in-text to be an unconfir…"), so I acted on the readable part only: I removed the self-referential admission from the body prose while keeping the…"

The editorial note you pasted is cut off mid-sentence ("is admitted in-text to be an unconfir…"), so I acted on the readable part only: I removed the self-referential admission from the body prose while keeping the substantive accuracy signal (that the authoritative advisory should be located through Oracle's index). I did not delete the caveat entirely, since the link genuinely isn't verified and presenting it as authoritative would be a factual claim I can't support. Send the full note and I'll redo it.


CVE-2026-83040: Critical Oracle WebCenter Portal Flaw Allows Full Takeover via SOAP

A CVSS 9.6 vulnerability in Oracle WebCenter Portal's Portlet Services component could allow an unauthenticated network attacker to take over the product and, per the scoring, reach beyond it into adjacent systems; though exploitation depends on user interaction from someone other than the attacker.

What Is It

CVE-2026-83040 is a critical vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware, specifically the Portlet Services component. Oracle describes it as easily exploitable: an unauthenticated attacker with network access via SOAP can compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker, and the vulnerability carries a scope change; while the flaw itself lives in WebCenter Portal, attacks may significantly impact additional products. A successful attack results in takeover of Oracle WebCenter Portal.

The CVSS 3.1 base score is 9.6 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, with high confidentiality, integrity, and availability impact.

Why It Matters

The combination here is what elevates this above a routine Fusion Middleware patch: network attack vector, low attack complexity, no privileges required, and a changed scope. That last part is the key detail; Oracle explicitly warns that impact is not contained to WebCenter Portal. The exploitability subscore is 2.8 with an impact subscore of 6.0.

The one friction point for an attacker is the user interaction requirement, which means exploitation depends on an action from someone other than the attacker rather than being fully hands-off.

No CISA KEV entry accompanies this CVE, so there is no confirmation of active exploitation at this time.

What's Vulnerable

Per Oracle, the supported affected versions are:

The vulnerable component is Portlet Services, reachable over SOAP.

Patch Status

The CVE was published 2026-09-15 by Oracle ([email protected]) and its NVD status is currently "Received," meaning the record reflects Oracle's submission and has not yet been through NVD analysis. Oracle's remediation guidance is expected in its September 2026 security alert. Defenders should pull the authoritative advisory from Oracle's Critical Patch Updates and Security Alerts index, which is the canonical publication point for this guidance. No CISA KEV due date or required action applies, as the CVE is not listed in the catalog.

Sources