Executive brief
Oracle WebCenter Portal is a web-based platform for building enterprise portals and collaboration sites. An unauthenticated remote vulnerability in the Portlet Services component allows attackers to gain complete control of the portal system, compromising all hosted applications, user data, and business operations without requiring authentication or user interaction.
Technical details
This vulnerability in Oracle WebCenter Portal's Portlet Services component is easily exploitable and requires only network access via HTTP. An unauthenticated attacker can exploit this flaw to achieve complete compromise of the Oracle WebCenter Portal instance, resulting in full takeover with impacts to confidentiality, integrity, and availability. The attack vector is network-based with no privilege escalation or user interaction required. Patches are expected to be available through Oracle's official security updates.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed