Executive brief
Oracle WebCenter Portal, a platform used by organizations to build and manage enterprise portals and intranets, contains a critical security flaw in its security framework. An unauthorized person can exploit this over the internet to gain full control of the portal. This could lead to the theft of sensitive corporate data, disruption of internal operations, and total loss of system integrity.
Technical details
A vulnerability classified as Missing Authentication for Critical Function (CWE-306) exists within the Security Framework component of Oracle WebCenter Portal. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTPS. It does not require user interaction or elevated privileges. Successful exploitation allows for a total compromise of confidentiality, integrity, and availability, effectively resulting in a complete system takeover. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle published security alert for June 2026