Junglewise Threat Intelligence

CVE-2026-46847: Oracle WebCenter Portal compromise in Runtime Tools

CVE-2026-46847 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle WebCenter Portal. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle WebCenter Portal, a platform used by organizations to build and manage enterprise portals and composite applications. A low-privileged user can exploit this flaw over the network to gain full control of the portal environment. This could lead to the theft of sensitive corporate data, disruption of business operations, and potential unauthorized access to other integrated systems.

Technical details

A vulnerability in the Runtime Tools component of Oracle WebCenter Portal (Oracle Fusion Middleware) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Notably, the vulnerability involves a 'scope change' (CVSS S:C), meaning a successful exploit can impact components or products beyond the immediate Oracle WebCenter Portal environment. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. While the specific CWE is not detailed in the advisory, the high CVSS score and scope change suggest a significant authorization bypass or injection-style flaw.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats