Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows an unauthenticated attacker with network access via HTTP to compromise the portal and gain full control, enabling the attacker to read, modify, or delete data and execute arbitrary requests. The flaw is an improper access control weakness (CWE-284) that can lead to loss of confidentiality, integrity, and availability of the application and its underlying data. Its severity is reflected in a CVSS 3.1 base score of 8.1, indicating a high-impact flaw if successfully exploited.

Affected Systems

The vulnerable Oracle WebCenter Portal releases are 12.2.1.4.0 and 14.1.2.0.0. Organizations running these versions should confirm that the latest patch or update from Oracle has been applied.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 indicates high severity. The EPSS score is reported as <1%, suggesting a low probability of exploitation, but the flaw still exposes a serious risk because it permits unauthenticated remote code execution via the HTTP interface, as the attacker does not need credentials. The vulnerability is not listed in the CISA KEV catalog, meaning no widespread active exploitation has been reported yet, yet the potential impact and the availability of the exposed interface warrant immediate attention.

Generated by OpenCVE AI on August 21, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Portal patch or update that addresses the Runtime Tools vulnerability.
  • Restrict external HTTP access to the portal by using firewall rules, VPN, or subnet isolation so that only trusted hosts can reach the application.
  • Enable detailed logging and monitoring on the portal to detect anomalous requests or unexpected access patterns.
  • If a patched version cannot be applied immediately, consider disabling or restricting the exposed HTTP endpoints that use the affected component to reduce the attack surface.

Generated by OpenCVE AI on August 21, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Portal Remote Code Execution via HTTP

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Portal Remote Code Execution via HTTP
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:21.078Z

Reserved: 2026-07-08T15:52:20.742Z

Link: CVE-2026-61229

cve-icon Vulnrichment

Updated: 2026-08-20T19:34:02.731Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:56.130

Modified: 2026-08-24T16:07:50.620

Link: CVE-2026-61229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:30:14Z

Weaknesses