Executive brief
Oracle WebCenter Portal is an enterprise content and collaboration platform used by organizations to share documents and manage team workspaces. A vulnerability in its Runtime Tools component allows an authenticated attacker to gain complete control over the portal, compromising data confidentiality, integrity, and availability of all portal services and content.
Technical details
This is a low-privileged authentication bypass or privilege escalation vulnerability in the Runtime Tools component of Oracle WebCenter Portal. The flaw is easily exploitable over HTTP by any low-privilege authenticated user without requiring user interaction (UI:N). An attacker with network access can leverage this to escalate privileges and fully compromise the affected system, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0; patch status is not confirmed from available sources.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed