Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Portal is vulnerable to an easily exploitable flaw that allows a low‑privileged attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical portal data, and to gain unauthorized access to all data accessible through the portal. The vulnerability requires human interaction from a user other than the attacker and can result in serious confidentiality and integrity losses without any impact on availability.

Affected Systems

The flaw affects Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0, which are part of the Oracle Fusion Middleware suite. These are the only editions identified as vulnerable in the vendor’s advisory.

Risk and Exploitability

The CVSS v3.1 Base Score of 8.7 indicates a high severity, reflecting high confidentiality and integrity impacts while availability is unaffected. EPSS score is less than 1% (0.00353), and the vulnerability is not listed in the CISA KEV catalog, so exact exploitation likelihood cannot be quantified, but the absence of a KEV listing does not imply low risk. The likely attack vector is network‑based via HTTP, and the vulnerability requires a cooperating user to trigger the action. The scope change indicates that successful exploitation could also affect additional Oracle products that interact with WebCenter Portal.

Generated by OpenCVE AI on August 21, 2026 at 12:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Portal security patch or update for versions 12.2.1.4.0 and 14.1.2.0.0
  • Restrict HTTP access to the portal to trusted IP ranges or isolated network segments to limit exposure
  • Enforce strict role‑based access controls so that only privileged users can create, delete, or modify critical data
  • Regularly audit user accounts and remove any unnecessary administrative permissions

Generated by OpenCVE AI on August 21, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Allows Unauthorized Data Modification in Oracle WebCenter Portal

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:20.468Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61219

cve-icon Vulnrichment

Updated: 2026-08-20T19:33:37.304Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:55.660

Modified: 2026-08-24T16:10:22.933

Link: CVE-2026-61219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:45:04Z

Weaknesses