Junglewise Threat Intelligence

CVE-2026-73952: Oracle WebCenter Portal unauthenticated access vulnerability in Portlet Services

CVE-2026-73952 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Oracle WebCenter Portal is an enterprise portal platform used for creating and managing business dashboards and collaborative workspaces. An unauthenticated network attacker can exploit a vulnerability in the Portlet Services component to gain unauthorized access to sensitive data or modify critical information without any authentication or user interaction required. This directly puts customer data at risk and could allow attackers to steal or corrupt entire portal datasets.

Technical details

This is an unauthenticated remote code execution or data access vulnerability in the Oracle WebCenter Portal Portlet Services component, accessible via HTTP protocol. The vulnerability requires no authentication, no complex configuration, and can be exploited over the network by any attacker with basic HTTP access. Successful exploitation allows an attacker to achieve both confidentiality and integrity impacts, including unauthorized creation, deletion, and modification of critical portal data or complete unauthorized access to all accessible data. The vulnerability affects Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0; patches or mitigations should be available through Oracle's security updates.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats