Executive brief
Oracle WebCenter Portal is a content management and collaboration platform used within Oracle Fusion Middleware deployments. A vulnerability in the Runtime Tools component allows authenticated attackers with network access to read sensitive data and make unauthorized modifications to portal content, potentially exposing customer information and enabling operational disruption.
Technical details
This is an easily exploitable authentication/authorization weakness in the Oracle WebCenter Portal Runtime Tools component, requiring low privileges and network-reachable HTTP access. The vulnerability allows an authenticated attacker to bypass authorization controls and gain unauthorized read and write access to portal data. Successful exploitation results in confidentiality and integrity compromise (CVSS 3.1 score 7.1). The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. Patches are expected from Oracle as part of their standard security release cycle.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed