Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle WebCenter Portal (Component: Runtime Tools) allows an attacker with network access over HTTP and low privileges to trigger an action requiring another user’s interaction. The flaw enables the attacker to obtain unauthorized access to critical data and to update, insert, or delete portal data. The impact includes a high confidentiality loss and a low integrity breach, as indicated by the CVSS 3.1 vector (C:H/I:L). The weakness is an improper access control flaw.

Affected Systems

The issue affects Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0. Due to the scope change, other integrated Oracle Fusion Middleware products could also be impacted when the portal is compromised.

Risk and Exploitability

The CVSS base score of 7.6 highlights moderate to high risk. The EPSS score of <1% indicates a low, but non‑zero, likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need network connectivity to the portal’s HTTP interface, low privileges on the target system, and the cooperation of a non‑attacker user to exploit the flaw. Given these conditions, the likelihood is moderate, but the potential for significant data breach makes timely mitigation crucial.

Generated by OpenCVE AI on August 21, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch released in August 2026 for Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as detailed in the Oracle Security Alert
  • Restrict HTTP access to the portal by configuring firewalls or VPNs so only trusted networks can reach it
  • Enforce multi‑factor authentication and ensure that user roles have the least privileges necessary for their functions

Generated by OpenCVE AI on August 21, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle WebCenter Portal

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle WebCenter Portal
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:20.765Z

Reserved: 2026-07-08T15:52:20.742Z

Link: CVE-2026-61227

cve-icon Vulnrichment

Updated: 2026-08-20T19:33:49.968Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:55.883

Modified: 2026-08-24T16:08:57.390

Link: CVE-2026-61227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses