ZeroHour

CVE-2026-73953

niche

Unauthenticated Remote Takeover in Oracle WebCenter Portal (Portlet Services, CVSS 9.8)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73953 is a critical (CVSS 9.8) vulnerability in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. Oracle describes it as easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. Successful exploitation can result in a complete takeover of the Oracle WebCenter Portal instance, with high impact on confidentiality, integrity, and availability. Organizations running the affected WebCenter Portal versions on networks reachable by attackers are at risk of full application compromise. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild appears unlikely at this time.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-73953 to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 deployments as a top priority. Until patched, restrict HTTP access to the portal at the network layer so only trusted users and VPN clients can reach it, and monitor logs for unexpected unauthenticated requests to Portlet Services endpoints. After remediation, review the instance for signs of compromise such as unauthorized administrative accounts or modified portal content.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component)12.2.1.4.0
Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component)14.1.2.0.0
Estimated exposure
nicheLikely low hundreds to low thousands of internet-reachable WebCenter Portal deployments worldwide — WebCenter Portal is an enterprise, often intranet-facing product with a small installed base relative to mainstream Oracle middleware, and public internet scans typically show only a small number of exposed WebCenter consoles; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.