Junglewise Threat Intelligence

CVE-2026-46767: Oracle WebCenter Portal improper access control in Composer

CVE-2026-46767 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle WebCenter Portal. Vendors: Oracle.

Executive brief

Oracle WebCenter Portal, a platform used for building enterprise portals and managing business content, contains a critical security vulnerability in its Composer component. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the portal. This could lead to the theft of sensitive corporate data, disruption of business operations, and potential unauthorized access to other connected systems.

Technical details

A vulnerability classified as Improper Access Control (CWE-284) exists in the Composer component of Oracle WebCenter Portal. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Due to a scope change (Status: Changed in CVSS), a successful exploit allows the attacker to not only take over the WebCenter Portal instance but also potentially impact additional products within the environment. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Security updates are typically provided via the Oracle Critical Patch Update (CPU) program.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats