Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-08-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This CVE describes a flaw in Oracle WebCenter Portal that enables a low-privileged attacker with network access via HTTP to bypass authorization controls and gain unauthorized read, write, and partial denial-of-service capabilities. The vulnerability can be triggered without authentication, allowing an attacker to obtain critical data or modify/delete portal content. The weakness corresponds to improper access control (CWE-284), forming the root cause of the unauthorized privileges and intrusion risk.

Affected Systems

Oracle Corporation’s WebCenter Portal product is affected in versions 12.2.1.4.0 and 14.1.2.0.0, as part of the Oracle Fusion Middleware stack. Administrative users may have deployed these releases in their environments, and any instance of WebCenter Portal running these versions is vulnerable. No other product variants or components are listed as impacted by this advisory.

Risk and Exploitability

The CVSS base score of 7.6 indicates a high severity due to confidentiality, integrity, and availability impact. Without an EPSS estimate, the exploitation probability is unknown, but the vulnerability is considered easily exploitable by a network attacker with standard HTTP access. It is not listed in the CISA KEV catalog, yet the risk remains significant given the urgent ability to compromise portal data and degrade service. An attacker could initiate unauthorized operations with minimal privileges, potentially escalating to broader compromise if the portal integrates with other internal systems.

Generated by OpenCVE AI on August 21, 2026 at 12:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle WebCenter Portal patch or upgrade to a fixed version as soon as it becomes available.
  • Restrict HTTP exposure of the portal by limiting access to trusted IP ranges, VPNs, or application-level firewalls to reduce the attack surface.
  • Implement robust monitoring of authentication and portal logs, setting alerts for anomalous read/write or failure events to detect and respond to abuse quickly.
  • Enforce least-privilege access controls and segregate the portal from other application layers to contain potential lateral movement.

Generated by OpenCVE AI on August 21, 2026 at 12:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Portal Vulnerability Enables Unauthorized Data Access and Partial DoS via HTTP

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Portal Vulnerability Enables Unauthorized Data Access and Partial DoS via HTTP
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:17.141Z

Reserved: 2026-07-08T15:52:20.740Z

Link: CVE-2026-61208

cve-icon Vulnrichment

Updated: 2026-08-19T12:12:56.413Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:55.160

Modified: 2026-08-20T15:05:28.700

Link: CVE-2026-61208

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:15:14Z

Weaknesses