Summary
CVE-2026-73963 is a critical, remotely exploitable vulnerability in the Portlet Services component of Oracle WebCenter Portal (part of Oracle Fusion Middleware). It allows an unauthenticated attacker with network access via HTTP to fully compromise the application, with successful exploitation resulting in complete takeover of the affected WebCenter Portal instance. Oracle rates this vulnerability as easily exploitable and disclosed it in the September 2026 Critical Security Patch Update (CSPU).
Technical details
- Root cause: A flaw in the Portlet Services component of Oracle WebCenter Portal that permits unauthorized actions to be performed without valid credentials.
- Trigger conditions: No authentication or user interaction is required; the vulnerability can be triggered solely via network requests to the exposed HTTP interface.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N) — the attacker needs only network access to the vulnerable HTTP service.
- Impact: Full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H), described by Oracle as resulting in complete takeover of Oracle WebCenter Portal.
Affected software
- Oracle WebCenter Portal 12.2.1.4.0
- Oracle WebCenter Portal 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Security Patch Update (CSPU) for September 2026, which contains the fix for CVE-2026-73963, to all affected Oracle WebCenter Portal deployments (versions 12.2.1.4.0 and 14.1.2.0.0).
- If immediate patching is not possible: Restrict network access to the Oracle WebCenter Portal Portlet Services HTTP endpoints to trusted internal networks only, and monitor internet-facing WebCenter Portal instances closely until the patch can be applied. Oracle explicitly recommends applying the CSPU fixes without delay due to the ease and severity of exploitation.

