Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Modification
Action: Patch Immediately
AI Analysis

Impact

A flaw in Oracle WebCenter Portal allows a high‑privileged attacker with HTTP network access to read, insert, update or delete data available through the portal. The vulnerability leads to a confidentiality impact that is considered high and an integrity impact considered low, as reflected in the CVSS v3.1 vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N. The issue is an Improper Access Control weakness (CWE-284).

Affected Systems

Oracle WebCenter Portal, versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability may cause a scope change that can impact other Oracle WebCenter products that rely on the same configuration or authentication mechanisms, as stated explicitly in the advisory.

Risk and Exploitability

The CVSS base score of 7.6 indicates a high severity attack that severely compromises confidentiality. The EPSS score is below 1%, suggesting a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The description explicitly requires the attacker to have high‑privileged credentials and to reach the portal over HTTP in order to exploit the access control flaw. If those conditions are met, the attacker can maintain access to all data exposed through the portal and potentially affect additional products due to the described scope change.

Generated by OpenCVE AI on September 17, 2026 at 05:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Portal security patch that addresses the high‑privilege data access flaw in versions 12.2.1.4.0 and 14.1.2.0.0.
  • Upgrade to a newer Oracle WebCenter Portal release that includes the vulnerability fix, if a patch is not yet available.
  • Restrict HTTP access to the portal by implementing firewall rules that limit connections to trusted IP addresses and enforce strong authentication.

Generated by OpenCVE AI on September 17, 2026 at 05:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title High Privilege Unauthorized Data Access via HTTP in Oracle WebCenter Portal

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:59:37.215Z

Reserved: 2026-08-31T15:40:57.335Z

Link: CVE-2026-83052

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:36.939Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:13.770

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:30:07Z

Weaknesses