Oracle has disclosed a CVSS 9.1 vulnerability in the Runtime Tools component of Oracle WebCenter Portal that allows a high-privileged network attacker to fully compromise the product, with a CVSS scope change indicating that impact may not be confined to WebCenter Portal itself.
What Is It
CVE-2026-83064 is a vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware, specifically the Runtime Tools component. Oracle describes it as easily exploitable, allowing a high-privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks can result in full takeover of the portal. Critically, although the flaw resides in WebCenter Portal, attacks may significantly impact additional products; a scope change in CVSS terms.
The CVSS 3.1 base score is 9.1 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. That breaks down to network attack vector, low attack complexity, high privileges required, no user interaction, changed scope, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of low attack complexity and changed scope is what elevates this above a routine middleware bug. An attacker who already holds high privileges on a WebCenter Portal instance does not need to chain complex steps; the exploit path is straightforward and requires no user interaction, and the changed scope means impact may extend past the vulnerable component to other products in the deployment. Oracle has not enumerated which additional products may be affected, so the practical blast radius will depend on how a given Fusion Middleware environment is composed. In deployments where WebCenter Portal sits alongside other trusted internal services, that scope change is the most consequential element of this disclosure.
The high privileges requirement is the one mitigating factor, but it does not eliminate risk from insider misuse, credential compromise, or an attacker who has already established a foothold elsewhere in the stack.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle WebCenter Portal (Oracle Fusion Middleware)
- Component: Runtime Tools
- Affected supported versions: 12.2.1.4.0 and 14.1.2.0.0
No CPE entries were published in the NVD record at the time of this writing.
Patch Status
The CVE was published on 2026-09-15 and is currently in NVD status Received, meaning NVD enrichment and analysis are not yet complete. Oracle's own advisory is the authoritative source for fix availability and patch levels; defenders should locate it via Oracle's security alerts index rather than relying on a constructed advisory URL, as the specific alert page referenced below does not follow Oracle's usual advisory naming pattern and has not been independently confirmed. As of publication, CVE-2026-83064 is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no confirmed public evidence of active exploitation in the wild and no KEV-mandated remediation deadline applies. Defenders should re-check the catalog directly, as listings are added on an ongoing basis.
Sources
- NVD, CVE-2026-83064: https://nvd.nist.gov/vuln/detail/CVE-2026-83064
- Oracle Security Alert (September 2026), link unverified, confirm against Oracle's security alerts index: https://www.oracle.com/security-alerts/cspusep2026.html
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog