Executive brief
Oracle WebCenter Portal is a content management and collaboration platform used in enterprise environments. A vulnerability in the Security Framework allows a low-privileged attacker with network access to bypass access controls and gain unauthorized access to sensitive data or modify portal content. The flaw impacts confidentiality and integrity of data stored in WebCenter Portal and potentially affects other connected systems.
Technical details
This is a privilege escalation or authentication bypass vulnerability in the Security Framework component of Oracle WebCenter Portal. The vulnerability is easily exploitable over HTTP (network-accessible) and requires only low-privileged user authentication—no additional interaction or complex preconditions are needed. An attacker can achieve unauthorized read access to critical data, as well as unauthorized modify/insert/delete operations on some portal data. The scope change indicates impact extends beyond WebCenter Portal itself to other Oracle Fusion Middleware components. Patch availability is expected through Oracle's standard security update channels.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed