Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the Oracle WebCenter Portal relies on improper access control allowing a low‑privileged user with HTTP network access to read and manipulate portal data. Successful exploitation can expose critical data and enable unauthorized updates, inserts, or deletions. The weakness is classified as CWE‑284. The CVSS 3.1 score of 7.1 reflects a high confidentiality impact and a moderate integrity impact.

Affected Systems

Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions were released as part of Oracle Fusion Middleware and remain supported by Oracle.

Risk and Exploitability

The exploit is relatively easy to perform over the network; an attacker needs only low privilege access and the ability to send HTTP requests to the portal. The EPSS value of < 1% suggests that public exploits have not yet been observed, but the CVSS score indicates a serious potential consequence if the vulnerability is hit. The vulnerability is not currently listed in the CISA KEV catalog. Administrators should consider the risk high enough to address promptly but can prioritize according to their threat model and exposure.

Generated by OpenCVE AI on September 17, 2026 at 03:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle WebCenter Portal to the latest patch level that includes the fix for the improper access control issue.
  • Restrict access to the web portal by configuring firewalls or reverse proxies to limit HTTP traffic to trusted networks only.
  • Review and harden user roles and permissions within the portal to enforce least privilege and reduce the potential impact of low‑privileged users.
  • Enable auditing and monitoring for anomalous read and write activity on portal data to detect potential exploitation.

Generated by OpenCVE AI on September 17, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploitation of Oracle WebCenter Portal

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:59:49.189Z

Reserved: 2026-08-31T15:40:57.335Z

Link: CVE-2026-83050

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:34.519Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:13.540

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:00:20Z

Weaknesses