Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A critical vulnerability exists in the Security Framework component of Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0. A low‑privileged attacker with network access over HTTPS can exploit the flaw to fully compromise the portal. The impact includes full confidentiality, integrity, and availability loss, effectively granting the attacker control of the entire application. The CVSS vector indicates that the vulnerability is remotely reachable, requires low authentication, and results in a scope change allowing privilege escalation.

Affected Systems

The affected products are Oracle WebCenter Portal from Oracle Corporation, specifically the 12.2.1.4.0 and 14.1.2.0.0 releases. Any instance of these versions deployed in an environment is susceptible unless mitigated.

Risk and Exploitability

The CVSS base score of 9.9 marks this flaw as critical, and the EPSS score of less than 1% indicates a low but nonzero current exploitation probability. Because the attack vector is over HTTPS, network‑level exposure is required; a user with minimal privileges can trigger the exploit. While the flaw is not listed in the CISA KEV catalog, its severity and potential to extend impact to other products make it a high priority for remediation.

Generated by OpenCVE AI on June 17, 2026 at 18:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a non-affected version of Oracle WebCenter Portal
  • Configure firewall and network controls to restrict HTTPS traffic to trusted IP addresses only and monitor for anomalous access attempts
  • If a patch is not immediately available, isolate the portal system from public networks and consider disabling unnecessary services to reduce the attack surface

Generated by OpenCVE AI on June 17, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:28:58.919Z

Reserved: 2026-05-18T15:55:10.305Z

Link: CVE-2026-46838

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T03:15:02Z

Weaknesses

No weakness.