CVE-2026-46847: Critical severity Oracle WebCenter Portal vulnerability
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle WebCenter Portal HTTPS endpoints: limit inbound HTTPS (TCP/443) to only trusted management IP addresses using firewalls/ACLs or place the portal behind a Web Application Firewall (WAF) or VPN so it is not directly reachable from untrusted networks.
- Operational
Investigate Oracle WebCenter Portal instances for signs of compromise (review access and application logs, authentication events, and configuration changes). If compromise is suspected, isolate affected hosts, perform forensic analysis, and rotate any administrative credentials and API keys used by Oracle WebCenter Portal.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46847?
The severity of CVE-2026-46847 is critical with a CVSS score of 9.9.
How do I fix CVE-2026-46847?
To fix CVE-2026-46847, apply the latest security patches provided by Oracle for affected versions.
What are the affected versions for CVE-2026-46847?
The affected versions for CVE-2026-46847 are 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Portal.
Who can exploit CVE-2026-46847?
CVE-2026-46847 can be exploited by a low privileged attacker with network access via HTTPS.
What type of vulnerability is CVE-2026-46847?
CVE-2026-46847 is an easily exploitable vulnerability in the Runtime Tools component of Oracle WebCenter Portal.