Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access and potential system compromise in Oracle WebCenter Portal
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in the Oracle WebCenter Portal product allows a low‑privileged attacker send HTTP requests to gain unauthorized access to critical data, potentially exposing all content managed by the portal. The weakness is an instance of improper access control, which gives the attacker the ability to read sensitive information that should be restricted. This flaw results in a high confidentiality impact while not directly affecting integrity or availability.

Affected Systems

Oracle Corporation’s WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. No other Oracle products are listed as directly impacted in the advisory.

Risk and Exploitability

The CVSS v3.1 base score is 7.7, indicating a medium‑to‑high severity. The EPSS score of less than 1 % suggests exploitation vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is network‑based via HTTP, requiring only local or remote network connectivity. The vulnerability’s scope change allows an attacker to affect additional products beyond the portal, magnifying its potential impact. Successful exploitation results in confidential data disclosure or complete data access for the affected portal instances.

Generated by OpenCVE AI on September 17, 2026 at 04:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Portal security patch for versions 12.2.1.4.0 and 14.1.2.0.0 to address this vulnerability.
  • Configure firewalls or ACLs to restrict HTTP access to the portal to trusted internal networks or VPN connections, thereby reducing the attack surface.
  • Enforce strict authentication and authorization controls, such as multi‑factor authentication and limited privileges for low‑privileged accounts, to prevent unauthorized access to sensitive configuration interfaces.

Generated by OpenCVE AI on September 17, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T18:00:01.681Z

Reserved: 2026-08-31T15:40:57.335Z

Link: CVE-2026-83048

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:29.868Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:13.313

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:00:14Z

Weaknesses