Executive brief
Oracle WebCenter Portal is a component of Oracle Fusion Middleware used to build enterprise web portals and collaborate on content. An unauthenticated attacker can exploit this vulnerability over the network to bypass authentication and gain unauthorized access to sensitive data stored in the portal, as well as modify or delete data. The vulnerability requires no user interaction and can be exploited by any attacker with network access.
Technical details
This is an authentication bypass vulnerability in the Runtime Tools component of Oracle WebCenter Portal affecting versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is easily exploitable and can be triggered via HTTP by an unauthenticated remote attacker without requiring any user interaction. Successful exploitation allows an attacker to access critical data and perform unauthorized create, read, update, and delete operations on WebCenter Portal accessible data. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N) indicates a network-based attack with no access control or user interaction required.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed