ZeroHour

CVE-2026-73948

niche

Authenticated Takeover Flaw in Oracle WebCenter Portal Composer

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73948 is a critical (CVSS 9.9) vulnerability in the Composer component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker holding only low-privileged credentials can exploit it over HTTP with no user interaction, and successful attacks result in a complete takeover of the WebCenter Portal deployment. The CVSS scope-change designation (S:C) means compromises can also significantly impact additional products beyond WebCenter Portal itself, with high confidentiality, integrity, and availability consequences. Only organizations running the two affected WebCenter Portal versions are exposed, and exploitation requires an authenticated session, so attackers would typically chain it with stolen or weak low-privilege credentials. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remedies this CVE to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 installations as soon as it is available, prioritizing any instance reachable over a network. Enforce strong authentication and least-privilege role assignments for portal users, and audit low-privilege accounts for suspicious activity or privilege changes. Because the flaw carries a scope change, also review and harden adjacent Fusion Middleware products integrated with the portal after patching.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, Composer component)12.2.1.4.0
Oracle WebCenter Portal (Oracle Fusion Middleware, Composer component)14.1.2.0.0
Estimated exposure
niche≈ hundreds to a few thousand deployments worldwide, with likely only hundreds internet-exposed — Oracle WebCenter Portal is an enterprise portal product with a limited mid-to-large-organization customer base and predominantly intranet-oriented deployments, so public scan services typically show only a few hundred internet-reachable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.