CVE-2026-73956
nicheUnauthenticated Takeover Flaw in Oracle WebCenter Portal Composer
CVE-2026-73956 is a critical (CVSS 3.1: 9.8) vulnerability in the Composer component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. An unauthenticated remote attacker with network access via HTTP can exploit it easily, and a successful attack can result in complete takeover of the Oracle WebCenter Portal instance, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0 and 14.1.2.0.0. The flaw is consistent with the unauthenticated, network-exploitable issues Oracle addresses in its quarterly Critical Patch Updates. There is no known public proof-of-concept, the issue is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remediates this issue to WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available. Until patched, restrict network access to the portal (especially Composer functionality) to trusted internal networks or VPN, and place the HTTP endpoints behind an authenticating reverse proxy. Review access and application logs for unauthenticated requests to Composer-related endpoints for signs of probing or compromise.
| Oracle WebCenter Portal (Oracle Fusion Middleware, Composer component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.