Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An easily exploitable flaw in Oracle WebCenter Portal, specifically within the Runtime Tools component, lets a low‑privileged threat actor with network access over HTTPS compromise the portal. Successful exploitation can result in full takeover, affecting confidentiality, integrity and availability of the application. The vulnerability is counted as a scope‑changing vector, meaning it can elevate the attacker’s privileges beyond their original level.

Affected Systems

Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These are part of Oracle Fusion Middleware and are delivered by Oracle Corporation.

Risk and Exploitability

The CVSS 3.1 base score of 9.9 indicates critical severity. With an EPSS score of less than 1 % the likelihood of exploitation is currently low, and the vulnerability is not listed in CISA’s KEV catalog. However, the impact is high: an attacker can achieve remote code execution and gain control of the portal. Attackers would need only network connectivity to the HTTPS endpoints and can launch the exploit with minimal privileges. System administrators should assess their exposure and apply remediation promptly.

Generated by OpenCVE AI on June 17, 2026 at 20:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 that addresses the Runtime Tools vulnerability.
  • If a patch is unavailable, restrict HTTPS access to the portal using network firewalls or VPNs, limiting exposure to trusted IP ranges and enforcing strict authentication.
  • Review and enforce proper role‑based access controls and authentication mechanisms in the portal to mitigate potential privilege escalation attacks.

Generated by OpenCVE AI on June 17, 2026 at 20:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:03:11.364Z

Reserved: 2026-05-18T15:55:10.306Z

Link: CVE-2026-46847

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T23:15:16Z

Weaknesses

No weakness.