A critical vulnerability, CVE-2026-46765, has been identified in Oracle WebCenter Portal, impacting supported versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability resides in the Composer component of Oracle Fusion Middleware. It allows a low-privileged attacker with network access via HTTP to compromise the Oracle WebCenter Portal. Although the vulnerability is specific to the portal, successful exploitation may lead to significant impacts on additional products due to scope changes. The CVSS 3.1 base score of 9.9 indicates a critical severity level, with high impacts on confidentiality, integrity, and availability. Organizations utilizing the affected versions of Oracle WebCenter Portal should prioritize assessing their exposure and applying the relevant security patches provided by Oracle. Immediate action is advised to prevent potential unauthorized access, data breaches, or system compromise. Users are encouraged to review Oracle's advisory for detailed mitigation steps and ensure all systems are up to date with the latest security updates.