Executive brief
Oracle WebCenter Portal, a platform used by organizations to build and manage collaborative intranets and portals, contains a critical security vulnerability in its Runtime Tools component. An unauthenticated attacker can exploit this flaw over the network to gain full control of the portal environment. This could lead to the theft of sensitive business data, unauthorized modification of portal content, and a complete disruption of portal services.
Technical details
A critical vulnerability exists in the Runtime Tools component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. While the specific vulnerability class (e.g., RCE, auth bypass) is not explicitly named in the advisory, the CVSS score of 9.8 and the 'takeover' impact indicate a complete loss of confidentiality, integrity, and availability. Attackers do not require any privileges or user interaction to execute the exploit. Organizations should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation guidance.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Vulnerability published in Oracle Critical Patch Update