Junglewise Threat Intelligence

CVE-2026-73948: Oracle WebCenter Portal privilege escalation in Composer

CVE-2026-73948 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Executive brief

Oracle WebCenter Portal is a portal and collaboration platform used to build enterprise web applications. A vulnerability in its Composer component allows an authenticated attacker with low privileges to completely compromise the portal and potentially impact other systems on the same network. Successful exploitation grants full administrative control and allows data theft or system disruption.

Technical details

This is a privilege escalation vulnerability in the Composer component of Oracle WebCenter Portal affecting versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is easily exploitable and requires only network access via HTTP plus low-level user credentials; no complex exploitation steps or user interaction are required. An authenticated attacker can leverage this flaw to achieve full system compromise with impact to confidentiality, integrity, and availability. The scope of impact extends beyond the affected component to other products, indicating potential for lateral movement or cascading failures across infrastructure. Oracle has assigned a CVSS 3.1 score of 9.9 (critical) and patches are expected to be available through normal Oracle security update channels.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats