Oracle WebCenter Portal: data tampering via Portlet Services
Critical9.1CVE-2026-73952 · Published Sep 15, 2026 · updated Sep 22, 2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Oracle WebCenter Portal Product | <= 12.2.1.4.0 | No fix yet |
| <= 14.1.2.0.0 | No fix yet |
Details and references
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | Oracle GraalVM for JDK: takeover via Compiler | High8.1 | No fix yet |
| Sep 15 | Oracle GraalVM for JDK: data tampering via Compiler | High7.0 | No fix yet |
| Sep 15 | Oracle GraalVM for JDK: takeover via Compiler | High8.1 | No fix yet |
| Sep 15 | Oracle VM VirtualBox: flaw in Core | Low3.2 | No fix yet |
| Sep 15 | Oracle VM VirtualBox: denial of service via Core | Medium6.0 | No fix yet |
| Sep 15 | Oracle GraalVM: takeover via Compiler | High8.1 | No fix yet |