Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Portal suffers an unauthenticated exploit that allows any network user with HTTP access to compromise the entire portal. The flaw resides in the Security Framework component and is formally classified as an improper authorization weakness, enabling attackers to gain full control over the application, resulting in confidentiality, integrity, and availability loss. The likelihood of exploitation is high because the vulnerability requires no credentials and can be triggered over the network.

Affected Systems

The affected releases are Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0. These versions are included in the Oracle Fusion Middleware stack and are commonly deployed in enterprise portal environments.

Risk and Exploitability

The CVSS 3.1 base score of 10.0 marks this as critical. EPSS indicates a very low probability (<1%) of immediate exploitation, yet the combination of no authentication and a network access vector makes the risk significant. The vulnerability is not listed in the CISA KEV catalog, but its scope change and total takeover potential mean it should be treated with the highest priority. Attackers can reach the vulnerable HTTP endpoints from any external network, implying unrestricted attack surface.

Generated by OpenCVE AI on June 17, 2026 at 21:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official security patch for WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as outlined in the Oracle security advisory
  • If a patch is not yet available, restrict HTTP/S access to the portal to trusted networks or enforce network segmentation to block unauthenticated traffic
  • Configure a web application firewall or intrusion detection system to alert on anomalous authentication‑less requests or suspicious HTTP patterns

Generated by OpenCVE AI on June 17, 2026 at 21:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:16:37.611Z

Reserved: 2026-05-18T15:55:10.300Z

Link: CVE-2026-46803

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T23:30:15Z

Weaknesses

No weakness.