Executive brief
Oracle WebCenter Portal is an enterprise portal platform used to build collaborative business applications. An unauthenticated attacker can exploit a vulnerability in the Portlet Services component via SOAP protocol to gain full control of the portal system, potentially compromising sensitive business data, disrupting operations, and affecting downstream applications that depend on it.
Technical details
This is a network-accessible vulnerability in the Portlet Services component of Oracle WebCenter Portal, exploitable via SOAP without authentication. The vulnerability requires human interaction from a user other than the attacker to trigger the exploit, indicating a social engineering or phishing vector may be involved. Successful exploitation results in complete takeover of the affected Oracle WebCenter Portal instance with high confidentiality, integrity, and availability impact. Affected versions are 12.2.1.4.0 and 14.1.2.0.0; patch availability should be confirmed through Oracle's security advisories.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed