ZeroHour

CVE-2026-73952

niche

Unauthenticated Data Access and Manipulation in Oracle WebCenter Portal (9.1)

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73952 is a critical (CVSS 9.1) vulnerability in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack lets the attacker create, delete, or modify critical data — or all data accessible to WebCenter Portal — as well as read critical data or gain complete access to all WebCenter Portal accessible data; availability is not impacted per the CVSS vector (C:H/I:H/A:N). Organizations running the affected portal versions, especially instances reachable over the network, are at risk of full compromise of portal content and confidentiality. There is no known public PoC, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-73952 to instances running WebCenter Portal 12.2.1.4.0 or 14.1.2.0.0 as soon as it is available, prioritizing any portal exposed to untrusted networks. Restrict HTTP access to WebCenter Portal and its Portlet Services endpoints via firewall rules or VPN-only access, and review logs for unauthenticated requests to portlet endpoints indicating tampering or data access.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
nichelikely hundreds to low thousands of internet-reachable instances; total enterprise deployments unknown — Oracle WebCenter Portal is a niche enterprise middleware product, and public internet scans for its web endpoints typically show only a small number of exposed servers, with most deployments internal to corporate networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.