Executive brief
Oracle WebCenter Portal, a platform used for building enterprise portals and managing business content, contains a critical security vulnerability in its Runtime Tools component. A low-privileged user can exploit this flaw over the network to gain full access to sensitive data or modify critical information within the portal. Because the exploit can impact other connected systems, it poses a significant risk to overall data integrity and corporate operations.
Technical details
This vulnerability exists in the Runtime Tools component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as a scope-changing vulnerability, meaning an exploit can affect components beyond the immediate security scope of the portal. An attacker with low-level privileges can exploit this over the network via HTTP without user interaction. Successful exploitation results in high confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of all accessible data. The CVSS 3.1 base score is 9.6, reflecting the significant impact and ease of exploitation. Users should refer to the Oracle July 2026 Critical Patch Update for remediation.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.