Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Portal contains an unauthenticated remote vulnerability that allows an attacker with network access via HTTP to compromise the portal. The flaw is an improper access control issue (CWE-284) that enables the attacker to read all data exposed by the portal, potentially exposing critical information. This breach of confidentiality can occur without any authentication or special privileges.

Affected Systems

Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability may also affect other related Oracle Fusion Middleware components due to scope changes as noted in the advisory.

Risk and Exploitability

The CVSS 3.1 Base Score is 8.6, indicating a high severity of potential data exposure. The EPSS score is 0.00303 (<1%), indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw simply by connecting to the web interface over HTTP with no authentication, making it easily exploitable. The scope change expands the risk, potentially affecting additional Oracle products that integrate with WebCenter Portal.

Generated by OpenCVE AI on August 21, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for WebCenter Portal v12.2.1.4.0 and v14.1.2.0.0 as released in the Oracle Security Alert Aug‑2026
  • Configure the portal to enforce authentication for all HTTP requests
  • Restrict network access by updating firewall rules to block unauthenticated HTTP exposure and allow only trusted IP ranges
  • Enable logging and monitoring for unauthorized access attempts to detect and respond to attacks

Generated by OpenCVE AI on August 21, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Portal Unauthenticated Remote Vulnerability

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:20.919Z

Reserved: 2026-07-08T15:52:20.742Z

Link: CVE-2026-61228

cve-icon Vulnrichment

Updated: 2026-08-20T19:33:56.007Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:56.000

Modified: 2026-08-24T16:08:24.103

Link: CVE-2026-61228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:30:14Z

Weaknesses