CVE-2026-73951
nicheUnauthenticated Takeover Flaw in Oracle WebCenter Portal Portlet Services
CVE-2026-73451 is a difficult-to-exploit vulnerability in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP who successfully exploits the flaw can fully compromise the WebCenter Portal instance, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1, vector AV:N/AC:H/PR:N/UI:N/S:U). The high attack complexity means exploitation requires conditions that are not fully controllable by the attacker, such as race conditions or specific environmental prerequisites, which lowers the likelihood of opportunistic mass attacks. Oracle addresses the flaw in its Critical Patch Update, and affected organizations running the two supported versions should treat patching as a priority despite the difficulty rating. There is no known public proof of concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, so no active exploitation has been reported to date.
What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-73451 to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 instances as soon as the patch is available in your maintenance cycle. Identify any WebCenter Portal HTTP endpoints (especially Portlet Services URLs) that are reachable from the internet or untrusted networks and restrict access via firewall rules, reverse proxies, or VPN. Review access and application server logs for unexplained administrative changes or anomalous unauthenticated requests to portlet endpoints as an indicator of attempted exploitation.
| Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.