A critical vulnerability (CVE-2026-46802) has been identified in Oracle WebCenter Portal, part of Oracle Fusion Middleware's Security Framework component. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise the affected system. The affected versions include 12.2.1.4.0 and 14.1.2.0.0. The CVSS 3.1 base score is 9.9, indicating a critical severity level with impacts on confidentiality, integrity, and availability. While the vulnerability is specific to Oracle WebCenter Portal, successful exploitation may lead to significant impacts on additional products due to scope changes. Organizations utilizing these affected versions are strongly advised to apply the latest security patches provided by Oracle to mitigate the risk of unauthorized access and potential system takeover. Immediate action is recommended to prevent exploitation by threat actors.