CVE-2026-73953
nicheUnauthenticated Remote Takeover in Oracle WebCenter Portal (Portlet Services, CVSS 9.8)
CVE-2026-73953 is a critical (CVSS 9.8) vulnerability in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. Oracle describes it as easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. Successful exploitation can result in a complete takeover of the Oracle WebCenter Portal instance, with high impact on confidentiality, integrity, and availability. Organizations running the affected WebCenter Portal versions on networks reachable by attackers are at risk of full application compromise. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild appears unlikely at this time.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-73953 to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 deployments as a top priority. Until patched, restrict HTTP access to the portal at the network layer so only trusted users and VPN clients can reach it, and monitor logs for unexpected unauthenticated requests to Portlet Services endpoints. After remediation, review the instance for signs of compromise such as unauthorized administrative accounts or modified portal content.
| Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component) | 12.2.1.4.0 |
| Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.