Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote System Takeover
Action: Immediate Patch
AI Analysis

Impact

Oracle WebCenter Portal’s Runtime Tools component has a vulnerability that allows a high‑privileged attacker with network access via HTTP to compromise the portal. The flaw can result in full takeover of the WebCenter Portal application, impacting confidentiality, integrity, and availability. The CVSS 3.1 vector indicates that the attack requires an attacker who already has high privileges on the target and is able to invoke the flaw over a network connection without user interaction.

Affected Systems

The affected products are Oracle WebCenter Portal version 12.2.1.4.0 and version 14.1.2.0.0. The vulnerability is documented by Oracle and the official advisory lists these two specific releases as impacted.

Risk and Exploitability

The CVSS base score of 9.1 marks the vulnerability as critical, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. It is not currently listed in the CISA KEV catalog. Based on the vector (AV:N/AC:L/PR:H), the attack requires an attacker with high privileges and a network path to the WebCenter Portal, likely via an exposed HTTP endpoint. Successful exploitation would give the attacker full control of the portal, potentially affecting other products that rely on it due to a scope change.

Generated by OpenCVE AI on September 17, 2026 at 03:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s Security Alerts for a patch specific to Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 and apply the update immediately
  • Restrict HTTP access to the Oracle WebCenter Portal to trusted networks or enforce VPN connectivity to limit exposure to high‑privileged attackers
  • Monitor audit logs and portal configuration for unauthorized changes or suspicious activity that could indicate an attempted takeover

Generated by OpenCVE AI on September 17, 2026 at 03:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Vulnerability in Oracle WebCenter Portal
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:10.723Z

Reserved: 2026-08-31T15:40:57.337Z

Link: CVE-2026-83064

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:15.150

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T03:45:20Z

Weaknesses