Executive brief
Oracle WebCenter Portal, a platform used for building enterprise portals and managing business applications, contains a critical security vulnerability in its Runtime Tools component. An attacker with low-level user credentials can exploit this flaw over the network to take complete control of the portal. This could lead to the theft of sensitive corporate data, disruption of business operations, and potential unauthorized access to other connected systems.
Technical details
A critical vulnerability exists in the Runtime Tools component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is categorized by a CVSS 3.1 score of 9.9 due to a 'Scope Change' (S:C), meaning an exploit can impact components beyond the immediate security scope of the portal. An attacker requires low-privileged (PR:L) authentication and network access via HTTP to execute the attack. Successful exploitation results in a complete compromise of Confidentiality, Integrity, and Availability, effectively allowing a full system takeover. Users are advised to apply the July 2026 Oracle Critical Patch Update.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released