Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Portal is affected by an easily exploitable flaw that permits a low‑privileged attacker with network access via HTTP to compromise the portal. Successful exploitation can lead to complete takeover, resulting in loss of confidentiality, integrity, and availability for portal data and services. The description indicates that the vulnerability can be triggered with minimal attacker privileges and without user interaction; it is inferred that the weakness possibly involves improper access control or authentication mechanisms.

Affected Systems

Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0, components of Oracle Fusion Middleware’s Runtime Tools, are the only products directly impacted by this CVE. No other vendors or product lines are listed as affected.

Risk and Exploitability

The CVSS Base Score of 8.8 indicates a high severity, and the EPSS score of <1% indicates that the overall exploitation probability is very low, though the vulnerability is technically easily exploitable via remote HTTP access with low privilege. Because the flaw is not listed in the CISA KEV catalog, no documented active exploits are known, but the combination of high impact and exposed HTTP interface warrants proactive mitigation. The likely attack path is through unauthenticated or low‑privileged HTTP requests that bypass proper access control, allowing takeover of the portal.

Generated by OpenCVE AI on August 21, 2026 at 12:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Oracle patch that addresses this issue as soon as it becomes available.
  • While a patch is pending, restrict inbound HTTP traffic to WebCenter Portal to trusted networks using firewall rules or VPN tunnels to block public internet exposure.
  • Enforce least privilege for portal accounts, disable excessive administrative permissions, and monitor application logs for anomalous privilege escalation or unauthorized admin activity.

Generated by OpenCVE AI on August 21, 2026 at 12:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP vulnerability could lead to portal takeover

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:20.123Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61213

cve-icon Vulnrichment

Updated: 2026-08-20T19:33:25.104Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:55.427

Modified: 2026-08-24T16:11:32.693

Link: CVE-2026-61213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:45:04Z

Weaknesses