Junglewise Threat Intelligence

CVE-2026-73959: Oracle WebCenter Portal privilege escalation in Composer

CVE-2026-73959 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Oracle WebCenter Portal is a collaboration and content management platform used by enterprises to build portals and user experiences. A vulnerability in the Composer component allows a low-privileged authenticated user to gain complete control over the portal system, including the ability to read sensitive data, modify content, and disrupt service availability. An attacker with network access and valid credentials can exploit this without user interaction.

Technical details

This is a privilege escalation vulnerability in the Oracle WebCenter Portal Composer component. The flaw allows a low-privileged user with network access via HTTP to compromise the entire portal system. The attack requires authentication (the attacker must have valid user credentials) but no special complexity or user interaction. Successful exploitation results in complete takeover of the portal, including unauthorized access to confidential data, ability to modify content and configuration, and potential for service disruption. No patch information is currently available from the provided advisory text.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats