Oracle has disclosed CVE-2026-73948, a critical vulnerability in the Composer component of Oracle WebCenter Portal that lets a low-privileged attacker with network access take over the product entirely.
What Is It
CVE-2026-73948 is a vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware, specifically in the Composer component. Oracle describes it as easily exploitable: an attacker with only low privileges and network access over HTTP can compromise Oracle WebCenter Portal. Successful attacks result in takeover of the product.
The CVSS 3.1 base score is 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. That breaks down to network attack vector, low attack complexity, low privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. The exploitability sub-score is 3.1 and the impact sub-score is 6.0.
Why It Matters
The scope is marked as changed. Oracle notes explicitly that while the vulnerability lives in Oracle WebCenter Portal, attacks may significantly impact additional products. That scope change is what pushes an already severe bug to 9.9; a compromise does not necessarily stop at the portal itself.
The privilege bar is low, not none, but "low privileged" in a portal product is a wide door. Combined with low attack complexity, no user interaction, and HTTP as the delivery path, this could be weaponized quickly, though no exploitation has been observed so far.
CISA KEV does not currently list CVE-2026-73948, so there is no confirmed active exploitation at this time and no federal remediation deadline attached to it.
What's Vulnerable
Per Oracle's advisory data, the affected supported versions of Oracle WebCenter Portal are:
- 12.2.1.4.0
- 14.1.2.0.0
The affected component is Composer. No CPE match data is present in the NVD record at this time.
Patch Status
The CVE was published on 2026-09-15 with an NVD status of "Received," meaning full NVD analysis is still pending. Remediation guidance comes from Oracle's security alerts and Critical Patch Update advisories, linked below; note that Oracle's scheduled Critical Patch Updates land in January, April, July, and October, so check that index for the advisory covering this CVE. No specific required action or deadline is stated in the supplied source material beyond Oracle's advisory. Organizations running either affected version should treat Oracle's advisory as the authoritative patch reference.
Sources
- Oracle Security Alerts and Critical Patch Updates; https://www.oracle.com/security-alerts/
- NVD, CVE-2026-73948, https://nvd.nist.gov/vuln/detail/CVE-2026-73948
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog