Executive brief
Oracle WebCenter Portal, a platform used by organizations to build and manage enterprise portals and intranets, contains a critical security flaw. An unauthorized person can remotely take full control of the portal over the internet without needing a username or password. This could lead to the theft of sensitive corporate data, a total shutdown of the portal service, or the compromise of other connected business systems.
Technical details
A vulnerability in the Security Framework component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0) is classified as CWE-306 (Missing Authentication for Critical Function). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Due to a scope change (Status: Changed), a successful exploit allows the attacker to not only take over the WebCenter Portal instance but also potentially impact additional products within the environment. The vulnerability has a CVSS 3.1 base score of 10.0, reflecting total loss of confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Security Alert published