Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Partial Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper access‑control flaw that allows an attacker with low privileges and network access via HTTP to read critical data and gain broad access to all data available through the WebCenter Portal. Successful exploitation can also induce a partial denial of service. The weakness is categorized as CWE-284. The impact is a loss of confidentiality and a degradation of availability, as described by the CVSS vector.

Affected Systems

Vendor Oracle delivers the affected product WebCenter Portal. The versions impacted are 12.2.1.4.0 and 14.1.2.0.0, which are part of the Oracle Fusion Middleware stack.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 indicates a high‑medium severity. The EPSS score of less than 1% implies a low probability of exploitation in the current environment, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based HTTP, requiring only low privileges to achieve impact.

Generated by OpenCVE AI on September 17, 2026 at 03:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict HTTP access to the portal to trusted networks or enforce authentication before any action.
  • Review and enforce least‑privilege permissions for all portal users and services.

Generated by OpenCVE AI on September 17, 2026 at 03:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Partial Denial of Service in Oracle WebCenter Portal

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:24:26.448Z

Reserved: 2026-08-31T15:40:57.335Z

Link: CVE-2026-83046

cve-icon Vulnrichment

Updated: 2026-09-16T15:55:07.524Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:13.087

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:00:20Z

Weaknesses