Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect access control flaw exists in the Runtime Tools component of Oracle WebCenter Portal. The flaw, categorized as CWE‑284, allows an attacker to send crafted HTTP requests without authentication and gain full control of the portal. Successful exploitation would lead to a complete compromise, exposing all stored data, allowing arbitrary code execution, and disrupting portal availability.

Affected Systems

The affected installations are Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware.

Risk and Exploitability

The vulnerability is rated with a CVSS v3.1 base score of 9.8, indicating a critical impact on confidentiality, integrity, and availability. The EPSS indicates a probability below 1%, so active exploitation attempts are unlikely at present, and the flaw is not currently included in CISA's KEV portfolio. Exploitation requires only network access to the portal’s HTTP interface; no credentials or out‑of‑band requirements are needed. If an attacker succeeds, they can completely take over the system, so the risk remains high.

Generated by OpenCVE AI on August 21, 2026 at 03:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch that addresses CVE‑2026‑70970 as published in the Oracle Security Advisory.
  • Limit inbound HTTP traffic to the WebCenter Portal by configuring firewall rules or VPN access so that only trusted IP ranges can reach the application.
  • Continuously monitor application logs and network traffic for anomalous HTTP requests or unauthorized activities.

Generated by OpenCVE AI on August 21, 2026 at 03:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Full Compromise via Unauthenticated HTTP Access to Oracle WebCenter Portal

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 20 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploit in Oracle WebCenter Portal Leads to Full Compromise
Weaknesses CWE-284

Wed, 19 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploit in Oracle WebCenter Portal Leads to Full Compromise
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:18:23.909Z

Reserved: 2026-08-04T22:06:34.609Z

Link: CVE-2026-70970

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:55.647

Modified: 2026-08-24T16:06:42.493

Link: CVE-2026-70970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T04:00:13Z

Weaknesses