Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Portal is vulnerable to remote exploitation through HTTP requests. An unauthenticated attacker can gain unauthorized creation, deletion or modification of critical data or all portal data, and can trigger a partial denial of service. The flaw is classified as a remote flaw with significant integrity and availability consequences, as reflected in the CVSS Base Score of 7.1.

Affected Systems

Affected systems include Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, as listed in the Oracle security alert. Patch status is not detailed in the available data.

Risk and Exploitability

The CVSS vector AV:N/AC:L/PR:N/UI:R indicates that a network attacker can exploit the vulnerability without authentication, but human interaction from a user other than the attacker is required to complete the attack. The EPSS score of <1% indicates a very low probability of exploitation, although insufficient data may still exist. The vulnerability is not listed in CISA’s KEV catalog, indicating no public evidence of active exploitation.

Generated by OpenCVE AI on August 21, 2026 at 12:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch referenced in the Oracle Security Alert CSPU Aug 2026
  • If a patch cannot be applied immediately, restrict network access to the portal by allowing only trusted IP addresses or enforcing VPN connectivity
  • Deploy a Web Application Firewall or similar solution to detect and block malicious HTTP requests to the portal

Generated by OpenCVE AI on August 21, 2026 at 12:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Vulnerability in Oracle WebCenter Portal

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:17.459Z

Reserved: 2026-07-08T15:51:55.614Z

Link: CVE-2026-61124

cve-icon Vulnrichment

Updated: 2026-08-19T12:13:03.371Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:54.297

Modified: 2026-08-20T15:05:34.510

Link: CVE-2026-61124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:15:14Z

Weaknesses