CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46845

Critical · CVSS 9.8

Oracle WebCenter Portal — Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-306

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Search profile — drives PoC discovery

Symbols Security FrameworkWebCenter PortalHTTPSunauthenticatedCWE-306CVE-2026-46845Oracle Fusion Middleware
Keywords CVE-2026-46845Oracle WebCenter Portal exploitWebCenter Portal unauthenticated takeoverWebCenter Portal Security Framework bypassOracle Fusion Middleware CVE-2026-46845 PoCWebCenter Portal 12.2.1.4.0 vulnerabilityWebCenter Portal 14.1.2.0.0 vulnerabilityCWE-306 Oracle WebCenterWebCenter Portal authentication bypass
Versions: 12.2.1.4.0, 14.1.2.0.0

References

Status: enriched · ingested 2026-06-23T06:00:15.000Z · profiled 2026-06-24T06:30:26.000Z