Executive brief
A critical vulnerability exists in Oracle WebCenter Portal, a platform used by organizations to build and manage enterprise portals and intranets. A low-privileged user can exploit this flaw over the network to take complete control of the portal environment. Because of the way the software is integrated, an attack could also spread to impact other connected business systems and data.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the Security Framework component of Oracle WebCenter Portal. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw is notable for its 'Scope Change' (S:C) designation, meaning a successful exploit allows the attacker to move beyond the portal's security boundaries to impact other components or products within the Oracle Fusion Middleware stack. Successful exploitation results in a total compromise of confidentiality, integrity, and availability (takeover) of the affected system. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published