Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits a low‑privileged attacker with network access via HTTP to gain unauthorized access to all data available in an Oracle WebCenter Portal instance. The flaw resides in the Runtime Tools component and can lead to data compromise because it bypasses established access controls. The impact is a confidentiality breach, as indicated by the CVSS vector, with no denial of service or integrity impact noted.

Affected Systems

The affected product is Oracle WebCenter Portal, version 14.1.2.0.0 of Oracle Fusion Middleware. No other versions or components are listed as impacted.

Risk and Exploitability

The CVSS base score is 7.7, reflecting significant confidentiality risk. The EPSS score of 0.0027 indicates a very low but non‑zero exploitation probability, meaning the vulnerability is still potentially exploitable despite the low likelihood. The CVE is not listed in the CISA KEV catalog, but the potential for widespread data exposure warrants a prioritized response. Attacks may be launched over the public network, so the primary vector is network‑based HTTP.

Generated by OpenCVE AI on August 21, 2026 at 13:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Portal patch for version 14.1.2.0.0 as outlined in the Oracle security alert.
  • Upgrade to a newer, supported release of Oracle WebCenter Portal that includes the fix.
  • If a patch or upgrade cannot be deployed immediately, restrict HTTP access to the portal by firewall or VPN to limit exposure to trusted hosts.
  • Review and reinforce the portal’s access control configuration to ensure that only properly authenticated users can access sensitive content.

Generated by OpenCVE AI on August 21, 2026 at 13:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via Low-Privileged HTTP Attack in Oracle WebCenter Portal Runtime Tools

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:19.799Z

Reserved: 2026-07-08T15:52:20.740Z

Link: CVE-2026-61199

cve-icon Vulnrichment

Updated: 2026-08-20T19:33:12.050Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:54.893

Modified: 2026-08-24T16:12:41.757

Link: CVE-2026-61199

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:15:05Z

Weaknesses