A CVSS 9.3 vulnerability in the Portlet Services component of Oracle WebCenter Portal lets an unauthenticated remote attacker read and modify all portal-accessible data, with impact spilling into adjacent products.
What Is It
CVE-2026-73957 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. The CVE record describes it as easily exploitable: an unauthenticated attacker with network access over HTTP can compromise the product. Successful attacks require human interaction from a person other than the attacker; consistent with the UI:R element of the CVSS vector.
The flaw carries a CVSS 3.1 base score of 9.3 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N. Confidentiality and integrity impacts are both HIGH; there is no availability impact. The scope is CHANGED, and the record notes that attacks may significantly impact additional products beyond WebCenter Portal itself.
Why It Matters
The combination of no required privileges, low attack complexity, and network reachability over HTTP puts this at the top of the triage list for any organization running WebCenter Portal. A successful attack yields unauthorized creation, deletion, or modification of critical data, or all data accessible to WebCenter Portal, plus unauthorized access to that same data. The scope change indicates that a compromise may not stay contained to the portal, and defenders should plan for impact on adjacent components.
The user-interaction requirement is the main source of friction, and in a portal product serving interactive users, that bar is likely to be a modest one.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle WebCenter Portal (Oracle Fusion Middleware)
- Component: Portlet Services
- Affected supported versions: 12.2.1.4.0 and 14.1.2.0.0
No CPE data is currently published for this CVE. The NVD record was published 2026-09-15 and remains in Received status, meaning NVD analysis is not yet complete.
Patch Status
No specific Oracle advisory for CVE-2026-73957 could be confirmed as published at the time of writing, and the Oracle link carried in the CVE metadata (listed below) does not resolve to a verifiable advisory. Oracle ships security fixes on a quarterly Critical Patch Update cycle, January, April, July, and October, so administrators should watch the next scheduled CPU and Oracle's security-alerts index for fixed-version guidance covering 12.2.1.4.0 and 14.1.2.0.0 deployments. Until then, treat mitigation as the near-term control: restrict network exposure of WebCenter Portal endpoints, particularly Portlet Services, to trusted networks.
No CISA KEV entry exists for CVE-2026-73957 at this time, so there is no confirmed active exploitation and no federal remediation deadline attached to it.
Sources
- Oracle security-alerts URL referenced in CVE metadata (unverified, does not resolve to a confirmed advisory), https://www.oracle.com/security-alerts/cpusep2026.html
- NVD, CVE-2026-73957, https://nvd.nist.gov/vuln/detail/CVE-2026-73957