Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Service Compromise
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the Composer component of Oracle WebCenter Portal. It allows a low‑privileged attacker who has network access through HTTP to compromise the portal. Successful exploitation can lead to a full takeover of the WebCenter Portal, affecting confidentiality, integrity, and availability. The weakness is an unauthorized access-284.

Affected Systems

This issue affects Oracle Corporation’s WebCenter Portal product, specifically versions 12.2.1.4.0 and 14.1.2.0.0. Only these releases are known to be vulnerable.

Risk and Exploitability

The CVSS v3.1 score of 8.8 marks the vulnerability as high severity, and the EPSS score of less than 1% indicates a low exploitation probability at present. The vulnerability is listed as not part of the CISA KEV catalog. It is exploitable via an unauthenticated HTTP request from a network‑attached attacker, making it potentially easy to leverage if the target is open to the Internet or an internal network.

Generated by OpenCVE AI on September 17, 2026 at 05:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for the WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 releases as provided by Oracle.
  • Restrict HTTP access to the portal by configuring firewall rules or network segmentation to limit traffic to trusted IP ranges.
  • Enforce strict authentication and review user permissions to ensure low‑privileged accounts cannot access Composer‑related functions.

Generated by OpenCVE AI on September 17, 2026 at 05:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title HTTP Authorization Bypass in Oracle WebCenter Portal Composer Component

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:29:17.066Z

Reserved: 2026-08-13T18:41:45.893Z

Link: CVE-2026-73959

cve-icon Vulnrichment

Updated: 2026-09-16T14:54:21.533Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:47.100

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-73959

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:45:18Z

Weaknesses