Executive brief
Oracle WebCenter Portal, a platform used for building enterprise portals and composite applications, contains a high-severity vulnerability in its Runtime Tools component. An attacker with low-level user credentials can exploit this flaw over the network to gain full control of the portal environment. This could lead to the unauthorized access of sensitive corporate data, modification of portal content, or a complete disruption of the service.
Technical details
This vulnerability exists within the Runtime Tools component of Oracle WebCenter Portal (part of Oracle Fusion Middleware). It is classified as easily exploitable, requiring only low-privileged user authentication and network reachability via HTTP. A successful exploit allows an attacker to achieve full compromise of the WebCenter Portal instance, impacting confidentiality, integrity, and availability. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. While the specific CWE is not detailed in the advisory, the impact suggests a significant authorization or injection flaw leading to complete system takeover.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Published as part of the Oracle Critical Patch Update (CPU) for July 2026.