Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to Portal data
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a flaw in the Runtime Tools component of Oracle WebCenter Portal that allows an unauthenticated attacker to access critical data or all accessible Portal data. This weakness is an authorization bypass, described as CWE‑284. The attacker need only send a crafted request over the network. Successful exploitation compromises confidentiality by exposing insecure data and can also provide full control over Portal resources.

Affected Systems

Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and are installed in many enterprise environments.

Risk and Exploitability

The CVSS 3.1 base score is 7.5, indicating a high risk to confidentiality. The EPSS score is < 1 %, suggesting exploitation is unlikely in the near term, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based HTTP traffic to the Portal. If exploited, an attacker can read confidential data and potentially gain complete data access without authentication.

Generated by OpenCVE AI on September 17, 2026 at 03:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's security patch or upgrade to a version that removes the affected Runtime Tools component.
  • If a patch cannot be applied immediately, restrict HTTP access to the Portal by placing it behind a web‑application firewall or an authentication proxy and blocking traffic from untrusted networks.
  • Configure network segmentation and firewall rules to limit inbound connections to the Portal only from approved internal hosts and monitor logs for anomalous connection attempts.

Generated by OpenCVE AI on September 17, 2026 at 03:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle WebCenter Portal Runtime Tools

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:59:42.928Z

Reserved: 2026-08-31T15:40:57.335Z

Link: CVE-2026-83051

cve-icon Vulnrichment

Updated: 2026-09-16T17:52:03.263Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:13.657

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:00:20Z

Weaknesses