Executive brief
Oracle WebCenter Portal is an enterprise portal platform used to build collaborative applications and manage enterprise content. An unauthenticated attacker can remotely compromise the entire portal system via a network-based exploit without requiring valid credentials or user interaction, potentially gaining full control over the application, its data, and operations.
Technical details
This vulnerability in the Portlet Services component of Oracle WebCenter Portal is easily exploitable and allows an unauthenticated attacker with network access via HTTP to achieve complete compromise. The vulnerability can be exploited without any authentication, user interaction, or complex conditions (CVSS AV:N, AC:L, PR:N, UI:N). Successful exploitation results in complete takeover of the affected WebCenter Portal system with impacts to confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0; patches are expected to be available through Oracle's security updates.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed