Junglewise Threat Intelligence

CVE-2026-46838: Oracle WebCenter Portal improper access control in Security Framework

CVE-2026-46838 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle WebCenter Portal. Vendors: Oracle.

Executive brief

Oracle WebCenter Portal, a platform used for building enterprise portals and managing business applications, contains a critical security vulnerability in its Security Framework. A user with low-level access to the system can exploit this flaw over the network to take full control of the portal. This could lead to the theft of sensitive corporate data, disruption of business operations, and potential unauthorized access to other connected enterprise systems.

Technical details

A vulnerability in the Security Framework component of Oracle WebCenter Portal (CWE-284: Improper Access Control) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Because the vulnerability involves a 'scope change' (CVSS S:C), a successful exploit can impact not only the WebCenter Portal itself but also other products and data within the Oracle Fusion Middleware environment. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats