A critical vulnerability, CVE-2026-46814, has been identified in Oracle WebCenter Portal, part of Oracle Fusion Middleware's Security Framework component. This vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. The flaw allows a low-privileged attacker with network access via HTTP to compromise the Oracle WebCenter Portal. Although the vulnerability is specific to the portal, attacks may have a broader impact on additional products due to scope changes. Successful exploitation could result in full system takeover, posing severe risks to confidentiality, integrity, and availability. Organizations utilizing the affected versions should prioritize applying the latest security patches provided by Oracle. Until patches are implemented, network access to the affected systems should be restricted, and security monitoring should be intensified to detect potential exploitation attempts. This vulnerability has a CVSS 3.1 score of 9.9, indicating a high severity level. Immediate action is recommended to mitigate the risk of unauthorized access and potential data breaches.
CRITICAL
CVSS 9.9
CVE-2026-46814
2026-08-25
Critical Vulnerability in Oracle WebCenter Portal (CVE-2026-46814)
A critical vulnerability in Oracle WebCenter Portal allows low-privileged attackers to take over the system via HTTP. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Immediate mitigation is required to prevent unauthorized access and system compromise.