CVE-2026-46802: critical vulnerability (CVSS 9.9)
CVE-2026-46802 is a critical vulnerability (CVSS 9.9) in Oracle WebCenter Portal's Security Framework, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A low-privileged attacker can exploit it remotely via HTTP, leading to portal takeover and potential impacts on other products.
This vulnerability's scope change emphasizes its cascading risk across dependent systems. Immediate patching and network segmentation for affected instances are critical to mitigate exposure.
Oracle WebCenter Portal's Security Framework contains a critical flaw that allows remote exploitation by low-privileged attackers. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0.
Successful exploitation can result in full compromise of the portal, with confidentiality, integrity, and availability impacts rated as high. The scope change means other connected products may also be affected.
Organizations should prioritize patching and consider additional mitigations, such as restricting HTTP access and monitoring for unusual activity in related systems.