Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-83043 2026-09-15

Oracle WebCenter Portal Composer Flaw Could Give Attackers Full Takeover (CVE-2026-83043)

"A critical flaw in the Composer component of Oracle WebCenter Portal could allow an unauthenticated remote attacker to take over the product, according to Oracle's description of the issue; and, per Oracle's own…"

A critical flaw in the Composer component of Oracle WebCenter Portal could allow an unauthenticated remote attacker to take over the product, according to Oracle's description of the issue; and, per Oracle's own scoring, the impact may extend beyond the portal into additional products.

What Is It

CVE-2026-83043 is a vulnerability in the Composer component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. Oracle describes it as easily exploitable by an unauthenticated attacker with network access over HTTP. Successful exploitation requires human interaction from someone other than the attacker, and results in takeover of Oracle WebCenter Portal.

The issue carries a CVSS 3.1 base score of 9.6 (Critical), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H. It was published on 2026-09-15 and currently sits in NVD with a status of "Received."

Why It Matters

The scoring tells the story. No privileges are required, attack complexity is low, and the attack vector is the network; the only gate is user interaction. Confidentiality, integrity, and availability impacts are all rated High. That user-interaction requirement is a real precondition, not a formality: an attacker still needs to induce action from a legitimate user, which shapes what a practical attack chain looks like.

Critically, the scope is Changed: Oracle states that while the vulnerability lives in WebCenter Portal, attacks "may significantly impact additional products." That is a statement about potential blast radius rather than a confirmed cross-system compromise path, but it is what pushes the score from high to critical territory, and it should be treated as a planning assumption until Oracle publishes more detail.

There is no CISA KEV entry for this CVE in the supplied source material, so there is no confirmation of active exploitation at this time. That is not a reason to deprioritize; a 9.6 in a widely deployed Fusion Middleware component is a well-lit target.

What's Vulnerable

Per Oracle, the affected product is Oracle WebCenter Portal (component: Composer), vendor Oracle Corporation. Supported versions listed as affected:

No affected CPE entries were present in the NVD record at time of writing.

Patch Status

The supplied source material attributes this vulnerability to an Oracle security advisory dated September 2026, but that attribution has not been confirmed against Oracle's own advisory listing. Oracle ships Critical Patch Updates on a fixed quarterly cadence, January, April, July, and October, so a September publication would have to be an out-of-cycle Security Alert rather than a CPU. The specific advisory path carried in the source material does not match Oracle's usual naming convention and should be treated as unconfirmed; locate the real advisory through Oracle's security alerts index before planning a patch window.

The supplied source material does not specify patch version numbers or a required remediation deadline; administrators should identify the authoritative Oracle advisory for fixed releases and apply them against the affected 12.2.1.4.0 and 14.1.2.0.0 deployments.

No KEV-mandated remediation due date applies, as the CVE is not present in the supplied KEV data.

Sources