Executive brief
Oracle WebCenter Portal is a component of Oracle Fusion Middleware that provides web content and collaboration features for enterprise users. This vulnerability allows a low-privileged user with network access to bypass authorization controls and view sensitive data across the system. Attackers could gain unauthorized access to confidential business information and intellectual property stored within the portal.
Technical details
This is a privilege escalation vulnerability in the Runtime Tools component of Oracle WebCenter Portal, exploitable via HTTP requests. The vulnerability has a low attack complexity and requires only low-level user privileges and network access; no user interaction is needed. A successful exploit enables an attacker to access critical data and confidential information across the platform, with scope change indicating impact to additional Oracle products. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0; patch availability is not specified in the advisory.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed