PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73957 Oracle Corporation CVE debrief

A critical vulnerability exists in Oracle WebCenter Portal, affecting versions 12.2.1.4.0 and 14.1.2.0.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise the portal, potentially impacting additional products. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to sensitive information.

Vendor
Oracle Corporation
Product
Oracle WebCenter Portal
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-22
Advisory published
2026-09-15
Advisory updated
2026-09-22

Who should care

Oracle WebCenter Portal administrators, security teams, and IT professionals responsible for patch management and vulnerability remediation should be aware of this critical vulnerability and take immediate action to assess exposure and apply necessary patches or mitigations.

Why it matters

CVE-2026-73957 is a critical vulnerability in Oracle WebCenter Portal that requires immediate attention from administrators and security teams. It allows unauthenticated attackers to potentially compromise the portal and access sensitive data, emphasizing the need for prompt patching and monitoring.

  • Potential unauthorized creation, deletion, or modification of critical data
  • Potential unauthorized access to sensitive information
  • Possible impact on additional products beyond Oracle WebCenter Portal
  • Need for human interaction to facilitate successful attacks

Technical summary

The vulnerability, tracked as CVE-2026-73957, is a critical issue in Oracle WebCenter Portal's Portlet Services component. It has a CVSS score of 9.3 and can be exploited by unauthenticated attackers with network access via HTTP. Successful attacks require human interaction and can lead to unauthorized data access or modification. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Portal and has a high impact on confidentiality and integrity. Administrators and security teams should prioritize patching and take immediate action to assess exposure and mitigate potential risks.

Defensive priority

High priority for Oracle WebCenter Portal administrators and security teams to assess exposure and apply patches or mitigations.

Recommended defensive actions

  • Assess exposure of Oracle WebCenter Portal instances to this vulnerability
  • Apply patches or mitigations provided by Oracle
  • Monitor for potential attacks and anomalous activity
  • Review and update incident response plans
  • Perform a thorough review of network configurations and access controls
  • Ensure that all instances of Oracle WebCenter Portal are properly patched and up-to-date
  • Review system logs for signs of potential exploitation attempts

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, its impact, and affected versions. Oracle has also released a security advisory related to this vulnerability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Portal. Defenders should verify patch applicability and assess exposure. Evidence is based on CVE and NVD data, which may have limitations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73957 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73957

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73957 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73957

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.