Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in the Composer component of Oracle WebCenter Portal allows an attacker with low privileges and network access via HTTP to achieve full control of the portal, affecting confidentiality, integrity, and availability. The problem appears to be an access‑control flaw that lets malicious requests bypass normal authorization, but this conclusion is inferred from the impact described in the CVE text.

Affected Systems

Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Systems running these releases are at risk unless patched or otherwise mitigated.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates high severity. The EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attack can be launched remotely over HTTP by a low‑privileged user, and no user interaction is required. The likely attack path involves sending a crafted request to the Composer component that bypasses authorization controls to take over the portal.

Generated by OpenCVE AI on August 21, 2026 at 15:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s security patch for WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 to fix the vulnerability.
  • Limit HTTP traffic to the portal by using firewall rules, VPN access, or IP whitelisting so that only trusted systems can reach web endpoints.
  • Harden the portal’s access controls by disabling unused services, enforcing strong authentication, and reviewing permission settings for sensitive operations.
  • Configure logging and monitoring to detect anomalous requests to the Composer component.

Generated by OpenCVE AI on August 21, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Exploit Allows Full Compromise of Oracle WebCenter Portal

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T17:37:41.385Z

Reserved: 2026-07-08T15:51:55.584Z

Link: CVE-2026-60729

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:40.873

Modified: 2026-08-20T15:18:00.353

Link: CVE-2026-60729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T15:45:18Z

Weaknesses