Junglewise Threat Intelligence

CVE-2026-46765: Oracle WebCenter Portal improper access control in Composer

CVE-2026-46765 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle WebCenter Portal. Vendors: Oracle.

Executive brief

Oracle WebCenter Portal, a platform used for building enterprise portals and managing business content, contains a critical security flaw in its Composer component. A user with even low-level access can exploit this vulnerability over the network to take full control of the portal. This could lead to the theft of sensitive corporate data, disruption of business operations, and potential unauthorized access to other integrated business systems.

Technical details

An improper access control vulnerability (CWE-284) exists in the Composer component of Oracle WebCenter Portal. The flaw is easily exploitable via HTTP by a low-privileged attacker with network access. Due to a scope change (Status: Changed), a successful exploit allows the attacker to compromise not only the WebCenter Portal instance but potentially impact additional integrated products. This can result in a complete takeover of the application, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Security Alert published

References

Related threats