Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the Runtime Tools component of Oracle WebCenter Portal and represents an improper access control (CWE-284) weakness, allowing an unauthenticated attacker with network access via HTTP to read privileged data and execute update or delete operations. This flaw bypasses authentication mechanisms and grants full access to all portal data, resulting in confidentiality and integrity compromise of sensitive information.

Affected Systems

Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is specific to those releases of the Oracle Fusion Middleware WebCenter Portal product.

Risk and Exploitability

The CVSS base score of 8.2 reflects a high severity, though the EPSS score is below 1%, indicating low current exploit activity, and the flaw is not listed in the CISA KEV catalog. Because the attack requires only unauthenticated HTTP access, the attacker can perform the vulnerability exploitation remotely from any network-connected system with visibility to the portal port. Once exploited, the attacker can read confidential data or alter records without legitimate credentials.

Generated by OpenCVE AI on September 20, 2026 at 12:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that addresses the vulnerability for versions 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict external HTTP traffic to the portal by enabling firewall rules that allow only trusted IP ranges or by requiring VPN access.
  • Ensure that the portal is not exposed directly to the internet; if necessary, move it behind a web application firewall or security gateway that can block malicious traffic.

Generated by OpenCVE AI on September 20, 2026 at 12:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploitation in Oracle WebCenter Portal Runtime Tools

Sun, 20 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access to Oracle WebCenter Portal via HTTP
Weaknesses CWE-306

Thu, 17 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access to Oracle WebCenter Portal via HTTP
Weaknesses CWE-306

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T18:00:11.785Z

Reserved: 2026-08-31T15:40:57.335Z

Link: CVE-2026-83047

cve-icon Vulnrichment

Updated: 2026-09-16T17:51:59.244Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:13.203

Modified: 2026-09-21T18:07:20.793

Link: CVE-2026-83047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:45:17Z

Weaknesses