Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Oracle WebCenter Portal allows low‑privileged attackers with network access via HTTP to obtain unauthorized access to critical data and to insert, update, or delete portal data. This weakness is classified as CWE‑284. The CVSS 3.1 score of 7.1 indicates a high confidentiality impact and a low integrity impact.

Affected Systems

Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Both versions are part of Oracle Fusion Middleware.

Risk and Exploitability

The vulnerability is easily exploitable over HTTP by a low‑privileged user. An attacker only requires network access with HTTP capability. The EPSS score is less than 1%, indicating few or no public exploits have been observed. The CVSS score of 7.1 indicates a high confidentiality impact and a low integrity impact. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 11:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or update that addresses the improper access control issue in Oracle WebCenter Portal.
  • Restrict HTTP access to the portal by configuring firewalls or reverse proxies to allow traffic only from trusted networks.
  • Review and enforce least privilege by hardening user roles and permissions within the portal to mitigate unauthorized data access.
  • Enable auditing and monitoring for read or write activities on portal data to detect and respond to potential exploitation.

Generated by OpenCVE AI on September 20, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploitation of Oracle WebCenter Portal

Thu, 17 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploitation of Oracle WebCenter Portal

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:59:49.189Z

Reserved: 2026-08-31T15:40:57.335Z

Link: CVE-2026-83050

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:34.519Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:13.540

Modified: 2026-09-21T18:06:58.730

Link: CVE-2026-83050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:30:17Z

Weaknesses