Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Portal Compromise via Unauthenticated SOAP Access
Action: Immediate Patch
AI Analysis

Impact

Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 contain a flaw in Portlet Services that permits an unauthenticated attacker to send SOAP requests and gain full control of the portal. Successful exploitation enables the attacker to read, modify, and delete data and to execute arbitrary commands with the same privileges as the portal, effectively taking over the entire application. The vulnerability is a classic Improper Access Control, as confirmed by its CWE-284 classification, and the lack of authentication checks on SOAP endpoints facilitates the compromise.

Affected Systems

The flaw affects Oracle WebCenter Portal operated by Oracle Corporation. The affected releases are Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0. Users deploying these versions must verify the installed product release and determine whether their environments are exposed to SOAP traffic from untrusted networks.

Risk and Exploitability

The CVSS v3.1 base score is 9.6, indicating significant confidentiality, integrity and availability impacts, while the EPSS score is below 1%, indicating a low but non‑zero likelihood of exploitation at present the CISA KEV catalog. Attackers must send specially crafted SOAP messages over the network; however, successful exploitation requires human interaction from a person an automated attack cannot fully succeed without another person’s involvement. The impact may extend beyond Oracle WebCenter Portal to other connected applications due to the scope change. The combination of a low EPSS and a high CVSS suggests that, although exploitation may not be widespread now, the vulnerability remains a severe threat if active exploitation occurs.

Generated by OpenCVE AI on September 17, 2026 at 04:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Portal patch or upgrade to a non‑ security alert
  • Restrict inbound SOAP traffic to the and implementing network segmentation
  • Enable additional authentication or multi‑factor controls on the portal to mitigate potential exploitation

Generated by OpenCVE AI on September 17, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:24:59.620Z

Reserved: 2026-08-31T15:40:57.334Z

Link: CVE-2026-83040

cve-icon Vulnrichment

Updated: 2026-09-16T15:43:39.321Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-15T20:18:12.410

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83040

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:00:14Z

Weaknesses