CVE-2026-73953

9.8

Oracle · WebCenter Portal

An unauthenticated remote code execution vulnerability exists in the Portlet Services component of Oracle WebCenter Portal, allowing full system takeover via HTTP.

Executive summary

A critical, unauthenticated remote takeover vulnerability in Oracle WebCenter Portal poses an extreme risk to organizational infrastructure.

Vulnerability

The flaw resides in the Portlet Services component of Oracle Fusion Middleware, permitting an unauthenticated attacker with network access to achieve full system compromise through simple HTTP requests.

Business impact

The vulnerability carries a CVSS base score of 9.8, indicating the highest level of severity. Successful exploitation results in complete loss of confidentiality, integrity, and availability, granting an attacker total control over the portal environment and potentially facilitating lateral movement into the broader corporate network.

Remediation

Immediate Action: Review the official Oracle security advisory at https://www.oracle.com/security-alerts/cspusep2026.html and apply the vendor-supplied patches as soon as they are released.

Proactive Monitoring: Inspect web server logs for suspicious HTTP requests targeting the Portlet Services component and monitor for unexpected administrative account creation or unauthorized process execution.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to filter or block anomalous traffic directed at the Portlet Services endpoint to mitigate the risk until patching is completed.

Exploitation status

Public Exploit Available: No (exploit_available unknown)

Analyst recommendation

This vulnerability represents a critical exposure that requires immediate attention from system administrators. Given the unauthenticated nature of the attack and the potential for full system compromise, organizations should treat this as a high-priority incident and apply vendor updates as soon as they become available.

More Oracle CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources