Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Security Framework component of Oracle WebCenter Portal, enabling a low‑privileged attacker with network access over HTTPS to compromise the target system. This flaw can lead to full takeover of the portal, exposing sensitive data and allowing modification or destruction of content. The flaw impacts confidentiality, integrity, and availability, and may extend beyond the portal to other Fusion Middleware products, as the description notes a scope change.

Affected Systems

Affected versions are Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0. These releases were identified under the CNA vendor Oracle Corporation for Oracle WebCenter Portal.

Risk and Exploitability

The CVSS 3.1 base score of 9.9 indicates critical severity, with low attack complexity and low required privileges but a change in scope. The EPSS score of less than 1% suggests low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description stating network access via HTTPS, the likely attack vector is an initial connection to the portal over HTTPS, after which the attacker can exploit the unsecured Security Framework to gain control. No user interaction or special conditions are required, making this vulnerability highly exploitable for an attacker who can reach the portal.

Generated by OpenCVE AI on June 17, 2026 at 18:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch released by Oracle or upgrade to a later, non‑vulnerable version of WebCenter Portal as advised in Oracle’s security alert.
  • Configure firewall or network segmentation to limit HTTPS traffic to the portal to trusted internal networks or authenticated users, reducing the attack surface.
  • Continuously monitor access logs and unauthorized activity patterns for indications of exploitation, and enforce least‑privilege access controls to mitigate potential lateral movement if the portal is compromised.

Generated by OpenCVE AI on June 17, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:31:32.741Z

Reserved: 2026-05-18T15:55:10.306Z

Link: CVE-2026-46844

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T03:15:02Z

Weaknesses

No weakness.