Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Runtime Tools component of Oracle WebCenter Portal and allows a low‑privileged attacker who can reach the system over HTTP to gain complete control of the portal. Successful exploitation can lead to takeover, exposing, altering, or denying the portal’s data. The weakness pertains to improper access control (CWE‑284).

Affected Systems

Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are impacted.

Risk and Exploitability

The CVSS v3.1 score of 8.5 indicates high confidentiality, integrity, and availability impact. EPSS is < 1% and the vulnerability is not currently listed in the CISA KEV catalog. The low‑privilege requirement and the need for only network‑based HTTP access suggest that external attackers could potentially reach the target from outside the organization. An attacker would likely need to send a specially crafted HTTP request; upon success they could execute arbitrary code or otherwise control the portal.

Generated by OpenCVE AI on August 21, 2026 at 12:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Portal patch provided in the Oracle security alert linked to this CVE
  • Restrict HTTP traffic to Oracle WebCenter Portal using firewall rules to allow only trusted internal networks
  • Enable and review audit logging for HTTP requests to detect anomalous activity

Generated by OpenCVE AI on August 21, 2026 at 12:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle WebCenter Portal Runtime Tools

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:19.950Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61212

cve-icon Vulnrichment

Updated: 2026-08-20T19:33:18.286Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:55.310

Modified: 2026-08-24T16:11:59.423

Link: CVE-2026-61212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:45:04Z

Weaknesses