ZeroHour

CVE-2026-73949

moderate

Privilege Escalation to Full Takeover in Oracle WebCenter Portal Portlet Services

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

A high-severity (CVSS 3.1: 8.8) vulnerability exists in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, requiring no user interaction. A successful attack allows the attacker to compromise Oracle WebCenter Portal entirely, with high impact on confidentiality, integrity, and availability — effectively a takeover of the portal instance. Any organization running the affected on-premises WebCenter Portal versions is at risk, particularly if the portal is reachable by broad or untrusted user populations. As of this analysis, there is no known public proof of concept and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no observed in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update fixes for Oracle WebCenter Portal covering versions 12.2.1.4.0 and 14.1.2.0.0 as soon as they are available for your quarterly CPU cycle. In the interim, restrict portal exposure to trusted networks, enforce least-privilege review of low-privileged accounts, and monitor for suspicious activity by authenticated users such as unexpected administrative changes or new privileged accounts.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component)
Estimated exposure
moderate≈ low thousands of internet-exposed portals, plus a larger but unmeasured population of intranet-only enterprise deployments (likely low tens of thousands of… — WebCenter Portal is a niche enterprise on-premises product; public internet scans (Shodan/FOFA-style fingerprinting of WebCenter/Fusion Middleware endpoints) typically show on the order of a few thousand internet-reachable instances, with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.