Junglewise Threat Intelligence

CVE-2026-73949: Oracle WebCenter Portal privilege escalation in Portlet Services

CVE-2026-73949 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Oracle WebCenter Portal is an enterprise portal framework used to build and manage web applications within Oracle Fusion Middleware. A vulnerability in its Portlet Services component allows an authenticated attacker with low-level access to gain complete control over the portal system. Successful exploitation could result in takeover of the entire portal platform, compromising confidentiality, integrity, and availability of business-critical applications and data.

Technical details

This vulnerability in Oracle WebCenter Portal's Portlet Services component is easily exploitable by a low-privileged attacker with network access via HTTP. The attack requires authentication (PR:L) but no user interaction (UI:N), and does not require special network conditions (AC:L). A successful exploit grants full control over Oracle WebCenter Portal, affecting confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0, and patches should be available through Oracle's security advisory process.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats