Executive brief
Oracle WebCenter Portal, a platform used for building enterprise portals and managing business applications, contains a critical security vulnerability in its Runtime Tools component. An attacker with basic user access can exploit this flaw over the network to take full control of the portal. This could lead to the theft of sensitive corporate data, disruption of business operations, and potential unauthorized access to other integrated systems.
Technical details
A critical vulnerability exists in the Runtime Tools component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is characterized by a 'scope change' (CVSS S:C), meaning a successful exploit can impact components beyond the immediate security scope of the WebCenter Portal. An attacker can achieve full compromise of the application, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial advisory publication by Oracle