Junglewise Threat Intelligence

CVE-2026-46802: Oracle WebCenter Portal improper access control in Security Framework

CVE-2026-46802 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle WebCenter Portal. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle WebCenter Portal, a platform used by organizations to build and manage enterprise portals and composite applications. An attacker with low-level user credentials can exploit this flaw over the network to gain full control of the portal environment. This could lead to the theft of sensitive corporate data, disruption of business operations, and potential unauthorized access to other integrated business systems.

Technical details

An improper access control vulnerability (CWE-284) exists in the Security Framework component of Oracle WebCenter Portal. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. A successful exploit allows for a complete takeover of the Oracle WebCenter Portal instance. Notably, the vulnerability includes a 'scope change' (CVSS S:C), meaning an attack can impact security properties of products beyond the WebCenter Portal itself. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats