CVE-2026-73959
nicheLow-Privilege Takeover Flaw in Oracle WebCenter Portal Composer
Oracle WebCenter Portal (Fusion Middleware), specifically its Composer component, contains an easily exploitable flaw that allows a low-privileged authenticated attacker with network access via HTTP to fully compromise the WebCenter Portal installation. Successful attacks result in complete takeover of the product, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Affected versions are 12.2.1.4.0 and 14.1.2.0.0. The flaw is triggered through standard HTTP requests from an already-authenticated low-privilege account, likely an authorization or input-handling weakness in Composer. There is no known public PoC and no confirmed in-the-wild exploitation as of this analysis, and the CVE is not on the CISA KEV list.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-73959 to all WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 installations as soon as possible. Restrict HTTP(S) access to the portal and the Composer component to trusted networks and authenticated users, and consider WAF/virtual-patching rules to block anomalous Composer requests in the interim. Review logs for unusual actions taken by low-privileged accounts, which would indicate post-exploitation behavior.
| Oracle WebCenter Portal (Oracle Fusion Middleware, component: Composer) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.