Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Composer component of Oracle WebCenter Portal, enabling a low‑privileged attacker with network access over HTTP to compromise the portal. The flaw can be exploited from a remote network, and successful exploitation leads to full takeover of the portal instance, impacting confidentiality, integrity, and availability. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) indicates a remote attack with low effort and controls various security properties.

Affected Systems

Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and are exposed to HTTP traffic.

Risk and Exploitability

The CVSS base score of 9.9 categorizes the flaw as critical. The EPSS score is not available, but the lack of a KEV listing does not diminish the potential impact. Since the attack vector is network‑based HTTP access and the attacker only requires low privileges, the likelihood of exploitation is high in environments where the portal is accessible from the internet or untrusted networks. The scope change indicates that additional products may be impacted if the portal is integrated with them.

Generated by OpenCVE AI on August 18, 2026 at 22:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle WebCenter Portal security patches or upgrade to a patched version that resolves the Composer component flaw.
  • Restrict HTTP access to the portal by implementing network segmentation or firewall rules that limit traffic to trusted hosts only.
  • Enforce least privilege on users interacting with the portal and monitor for anomalous activity to detect potential exploitation attempts.

Generated by OpenCVE AI on August 18, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle WebCenter Portal Composer via HTTP
Weaknesses CWE-284
CWE-77

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:03.021Z

Reserved: 2026-07-08T15:51:55.584Z

Link: CVE-2026-60730

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:40.987

Modified: 2026-08-18T21:16:40.987

Link: CVE-2026-60730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:00:14Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')