ZeroHour

CVE-2026-73963

moderate

Unauthenticated HTTP Takeover Flaw in Oracle WebCenter Portal Portlet Services (CVSS 9.8)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73963 is a critical (CVSS 9.8) vulnerability in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. A successful attack allows complete takeover of the Oracle WebCenter Portal instance, with high impact on confidentiality, integrity, and availability. Organizations running the affected on-premises portal deployments exposed to network attackers are at risk of full system compromise. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-73963 to WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available, prioritizing any instance reachable over HTTP. Until patched, restrict or block external HTTP access to Portlet Services endpoints via firewall rules or a WAF, and require authentication at a reverse proxy. Review logs and the portal for signs of compromise such as unexpected administrative accounts or configuration changes, since successful exploitation yields full takeover.

Affected
Oracle WebCenter Portal (Oracle Fusion Middleware, Portlet Services component)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
moderatelikely on the order of a few thousand internet-reachable installations — WebCenter Portal is niche enterprise on-premises middleware rather than a mass-market product, and public internet-wide scans of Oracle Fusion Middleware deployments historically show only low-thousands of exposed WebCenter endpoints; this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.