Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Compromise of the Oracle WebCenter Portal
Action: Immediate Patch
AI Analysis

Impact

Oracle WebCenter Portal’s Portlet Services component contains a flaw that allows attackers who have network connectivity and do not need privileged credentials to execute arbitrary actions within the portal. The vulnerability can be triggered through crafted HTTP requests, resulting in a complete takeover of the portal instance. An attacker who successfully exploits this flaw can read, modify, or delete data, and potentially disrupt the portal’s availability. The impact covers confidentiality, integrity, and availability and is classified as Remote Compromise of the application.

Affected Systems

Oracle WebCenter Portal, versions 12.2.1.4.0 and 14.1.2.0.0, distributed as Oracle Fusion Middleware. The vulnerability is present in the Portlet Services component of these releases.

Risk and Exploitability

The high CVSS Base Score of 8.8 reflects severe remote code execution potential, while an EPSS score of < 1% indicates a low but non-zero probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted HTTP requests over a network that has access to the portal, requiring only low privilege and no prior authentication. Detection relies on monitoring for anomalous portlet activity and HTTP request patterns.

Generated by OpenCVE AI on September 17, 2026 at 05:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Portal security update that addresses the Portlet Services vulnerability.
  • Restrict HTTP access to the portal to trusted networks and users by configuring firewall rules or reverse proxy authentication.
  • Enforce strict role‑based access control for portal operations to prevent unauthorized invocation of privileged portlet services.
  • Monitor portal logs for suspicious activity such as unexpected POST requests or elevated privilege actions.

Generated by OpenCVE AI on September 17, 2026 at 05:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Portal RCE via Portlet Services
Weaknesses CWE-95

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:29:51.604Z

Reserved: 2026-08-13T18:41:45.892Z

Link: CVE-2026-73949

cve-icon Vulnrichment

Updated: 2026-09-16T14:54:07.714Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:46.023

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-73949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:15:19Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-95

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')