Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Modification
Action: Immediate Patch
AI Analysis

Impact

The flaw is an access‑control weakness in the Portlet Services component of Oracle WebCenter Portal, allowing an unauthenticated attacker to create, delete, or modify data when they successfully interact with an HTTP endpoint. The vulnerability can lead to loss of confidentiality and integrity of critical data, and can be leveraged to obtain full access to all portal data. The weakness is characterized by CWE‑284, an incorrect implementation of access restrictions.

Affected Systems

Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 are affected. Any installation of these versions that exposes the HTTP port to external networks is at risk; the impact may extend to other Oracle Fusion Middleware components that rely on the same Portal services.

Risk and Exploitability

The CVSS 3.1 base score of 9.3 reflects a high severity with significant confidentiality and integrity impact. The EPSS score indicates a very low but non‑zero probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need network access to the exposed HTTP port and human interaction to trigger the flaw, but the requirement for direct interaction does not reduce the risk of a successful compromise for a motivated actor.

Generated by OpenCVE AI on September 17, 2026 at 05:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses access‑control issues in WebCenter Portal for the affected versions.
  • Restrict external network reach port VPN so only trusted internal hosts can reach the service.
  • Disable or secure any unused Portlet Services and enforce strict role‑based access controls to ensure only authorized users can perform create, delete, or modify operations.

Generated by OpenCVE AI on September 17, 2026 at 05:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control Vulnerability in Oracle WebCenter Portal

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:29:27.979Z

Reserved: 2026-08-13T18:41:45.893Z

Link: CVE-2026-73957

cve-icon Vulnrichment

Updated: 2026-09-16T14:54:17.263Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:46.887

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-73957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:45:18Z

Weaknesses