Executive brief
Oracle WebCenter Portal, a platform used for building enterprise portals and managing business applications, contains a critical security flaw in its Security Framework. An unauthorized person can remotely take full control of the portal over the internet without needing a username or password. This could lead to a total loss of data confidentiality and service availability, potentially impacting other connected business systems.
Technical details
A critical vulnerability exists in the Security Framework component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is categorized as a missing authentication for a critical function (CWE-306), allowing an unauthenticated attacker with network access via HTTP to bypass security controls. Due to a scope change (CVSS S:C), an exploit not only allows for a complete takeover of the WebCenter Portal instance but may also facilitate attacks against other products within the environment. The vulnerability is considered easily exploitable with no user interaction required. Users should refer to the Oracle June 2026 Security Alert for patching information.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Security Alert published