Executive brief
Oracle WebCenter Portal is a collaborative web application platform used for enterprise content and team workspaces. This vulnerability allows an unauthenticated attacker to fully compromise the portal through a network exploit requiring minimal user interaction, potentially affecting connected systems and risking unauthorized access to sensitive business data and collaboration content.
Technical details
This is a remote code execution vulnerability in the Composer component of Oracle WebCenter Portal accessible via HTTP. The vulnerability is easily exploitable by unauthenticated network attackers but requires social engineering or user interaction from a non-attacker. Successful exploitation results in complete system compromise with impacts to confidentiality, integrity, and availability. The scope changes, meaning attacks on this component can significantly impact other connected products within the Fusion Middleware stack. Patches are available from Oracle's security updates.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed