CVE-2026-73963
moderateUnauthenticated HTTP Takeover Flaw in Oracle WebCenter Portal Portlet Services (CVSS 9.8)
CVE-2026-73963 is a critical (CVSS 9.8) vulnerability in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. A successful attack allows complete takeover of the Oracle WebCenter Portal instance, with high impact on confidentiality, integrity, and availability. Organizations running the affected on-premises portal deployments exposed to network attackers are at risk of full system compromise. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not on the CISA Known Exploited Vulnerabilities list.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-73963 to WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available, prioritizing any instance reachable over HTTP. Until patched, restrict or block external HTTP access to Portlet Services endpoints via firewall rules or a WAF, and require authentication at a reverse proxy. Review logs and the portal for signs of compromise such as unexpected administrative accounts or configuration changes, since successful exploitation yields full takeover.
| Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.