ZeroHour

CVE-2026-73951

niche

Unauthenticated Takeover Flaw in Oracle WebCenter Portal Portlet Services

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-73451 is a difficult-to-exploit vulnerability in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP who successfully exploits the flaw can fully compromise the WebCenter Portal instance, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1, vector AV:N/AC:H/PR:N/UI:N/S:U). The high attack complexity means exploitation requires conditions that are not fully controllable by the attacker, such as race conditions or specific environmental prerequisites, which lowers the likelihood of opportunistic mass attacks. Oracle addresses the flaw in its Critical Patch Update, and affected organizations running the two supported versions should treat patching as a priority despite the difficulty rating. There is no known public proof of concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, so no active exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-73451 to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 instances as soon as the patch is available in your maintenance cycle. Identify any WebCenter Portal HTTP endpoints (especially Portlet Services URLs) that are reachable from the internet or untrusted networks and restrict access via firewall rules, reverse proxies, or VPN. Review access and application server logs for unexplained administrative changes or anomalous unauthenticated requests to portlet endpoints as an indicator of attempted exploitation.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
nichelikely on the order of low thousands of enterprise deployments worldwide, mostly internal-facing (clearly an estimate) — Oracle WebCenter Portal is licensed enterprise middleware typically deployed on-premises by large organizations and usually restricted to internal networks, and no public install counts or exposed-device telemetry were provided in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.