Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Portal executes to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Compromise of Oracle WebCenter Portal
Action: Patch Immediately
AI Analysis

Impact

A flaw in the Runtime Tools component of Oracle WebCenter Portal allows an unauthenticated attacker who has physical or local access to the server to bypass authentication and take over classified as CWE‑284 (Improper Access Control) and also aligning with CWE‑285 (Improper Authorization), leads to loss of confidentiality, integrity, and availability for the portal, granting the attacker full control of the system. The attack requires an attacker to be present on the same physical network segment as the hardware running the portal, which is inferred from the description that the “unauthenticated attacker with access to the physical communication segment” can exploit the flaw.

Affected Systems

Oracle WebCenter Portal, version 14.1.2.0.0. This is the sole version identified by the CNA as affected.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 indicates a high severity vulnerability. The EPSS score of less than 1% points to a low likelihood of exploitation in the wild, although the risk is elevated once an attacker gains the necessary physical or local access. The flaw is not listed in the CISA KEV catalog, so it is not known to be actively exploited at scale. Because the exploitation local access, the potential impact is limited to environments where physical or local host compromise is possible, but any successful attack results in total takeover of the portal.

Generated by OpenCVE AI on September 17, 2026 at 04:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Oracle WebCenter Portal security patch or upgrade to a non‑affected release such as 14.1.2.1 or later.
  • Restrict physical and local access to the servers hosting Oracle WebCenter Portal by implementing strict facility and hardware security controls.
  • Isolate the portal’s network segment from other systems to reduce lateral movement opportunities.
  • Monitor system and application or configuration changes.

Generated by OpenCVE AI on September 17, 2026 at 04:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Enables Portal Takeover
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Portal executes to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:11.046Z

Reserved: 2026-08-31T15:40:57.337Z

Link: CVE-2026-83065

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:15.323

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83065

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:30:08Z

Weaknesses