CVE-2026-73949
moderatePrivilege Escalation to Full Takeover in Oracle WebCenter Portal Portlet Services
A high-severity (CVSS 3.1: 8.8) vulnerability exists in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, requiring no user interaction. A successful attack allows the attacker to compromise Oracle WebCenter Portal entirely, with high impact on confidentiality, integrity, and availability — effectively a takeover of the portal instance. Any organization running the affected on-premises WebCenter Portal versions is at risk, particularly if the portal is reachable by broad or untrusted user populations. As of this analysis, there is no known public proof of concept and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no observed in-the-wild exploitation.
What to do: Apply the Oracle Critical Patch Update fixes for Oracle WebCenter Portal covering versions 12.2.1.4.0 and 14.1.2.0.0 as soon as they are available for your quarterly CPU cycle. In the interim, restrict portal exposure to trusted networks, enforce least-privilege review of low-privileged accounts, and monitor for suspicious activity by authenticated users such as unexpected administrative changes or new privileged accounts.
| Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.