Summary
CVE-2026-73952 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal (part of Oracle Fusion Middleware). It allows an unauthenticated, network-based attacker to compromise the application over HTTP, resulting in unauthorized creation, deletion, or modification of critical data as well as full read access to all data accessible to WebCenter Portal. Oracle rates the flaw as "easily exploitable" with a CVSS 3.1 base score of 9.1 (Critical).
Technical details
- Root cause: An access-control weakness in the Portlet Services component of Oracle WebCenter Portal that fails to properly restrict operations reachable over HTTP.
- Trigger conditions: No authentication or user interaction is required; the vulnerable functionality is reachable directly over the network via HTTP.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High confidentiality impact and high integrity impact — successful exploitation can grant an attacker unauthorized access to all data accessible through WebCenter Portal and let them create, modify, or delete that data. Availability is not affected (A:N).
Affected software
- Oracle WebCenter Portal 12.2.1.4.0
- Oracle WebCenter Portal 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Security Patch Update that addresses CVE-2026-73952 for the affected WebCenter Portal release (12.2.1.4.0 or 14.1.2.0.0), as published in Oracle’s security alerts program. Oracle strongly recommends applying the fix as soon as possible since the vulnerability is remotely exploitable without authentication.
- If immediate patching is not possible: Restrict network exposure of WebCenter Portal and its Portlet Services endpoints — limit access to trusted internal networks or VPN, and place the application behind a properly configured WAF/reverse proxy that can filter anomalous or unauthenticated portlet requests. Monitor access and audit logs for unexpected data creation, modification, or deletion activity as an interim compensating control until patching is complete.

