Executive brief
A critical vulnerability exists in Oracle WebCenter Portal, a platform used by organizations to build and manage enterprise portals and intranets. An attacker with low-level user credentials can exploit this flaw over the network to take full control of the portal environment. This could lead to the theft of sensitive corporate data, disruption of business operations, and potential unauthorized access to other connected enterprise systems.
Technical details
An improper access control vulnerability (CWE-284) exists in the Security Framework component of Oracle WebCenter Portal. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Successful exploitation results in a 'scope change' (CVSS S:C), meaning the attacker can move beyond the portal's security boundaries to impact other integrated products. This can lead to a complete takeover of the WebCenter Portal instance, compromising confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory