ZeroHour

CVE-2026-73956

niche

Unauthenticated Takeover Flaw in Oracle WebCenter Portal Composer

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73956 is a critical (CVSS 3.1: 9.8) vulnerability in the Composer component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. An unauthenticated remote attacker with network access via HTTP can exploit it easily, and a successful attack can result in complete takeover of the Oracle WebCenter Portal instance, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0 and 14.1.2.0.0. The flaw is consistent with the unauthenticated, network-exploitable issues Oracle addresses in its quarterly Critical Patch Updates. There is no known public proof-of-concept, the issue is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates this issue to WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available. Until patched, restrict network access to the portal (especially Composer functionality) to trusted internal networks or VPN, and place the HTTP endpoints behind an authenticating reverse proxy. Review access and application logs for unauthenticated requests to Composer-related endpoints for signs of probing or compromise.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, Composer component)
Estimated exposure
nichelikely low thousands of deployments worldwide, with only hundreds to low thousands internet-exposed — WebCenter Portal is an enterprise on-premises portal product with a limited installed base, and public internet scan data for Oracle WebCenter endpoints typically shows only small exposed counts compared to mass-market software.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.