Sceawere

Vulnerability Detail

CVE-2026-70970UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle WebCenter Portal Remote Takeover

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle WebCenter Portal
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-18T21:17:55.647Z",
  "pubdate": "2026-08-18T21:17:55.647Z",
  "executiveSummary": "A critical security vulnerability affects the Oracle WebCenter Portal product of Oracle Fusion Middleware, specifically within the Runtime Tools component. The vulnerability impacts supported versions 12.2.1.4.0 and 14.1.2.0.0. This flaw allows an unauthenticated remote attacker with network access via HTTP to fully compromise the target system without requiring any user interaction.\nSuccessful exploitation of this vulnerability results in a complete takeover of Oracle WebCenter Portal, yielding severe impacts across confidentiality, integrity, and availability. The CVSS 3.1 Base Score is 9.8 with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Due to the lack of authentication requirements and low complexity of attacks, the risk implications are critical, potentially enabling malicious actors to execute arbitrary actions, access sensitive data, modify system configurations, or disrupt critical business services hosted within the affected portal infrastructure.",
  "technicalDetails": "The vulnerability resides within the Runtime Tools component of Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0. The root cause enables unauthenticated remote code execution or authorization bypass via network requests sent over the HTTP protocol. Because the vulnerable component fails to properly validate incoming requests or restrict unauthorized access, external entities can interact directly with sensitive internal functions exposed by the portal.\nThe exploitation method requires network connectivity to the HTTP service hosting Oracle WebCenter Portal. An attacker initiates the attack flow by crafting specialized HTTP requests targeting the vulnerable Runtime Tools component. Since the attack vector is network-based (AV:N) with low attack complexity (AC:L), and requires zero privileges (PR:N) or user interaction (UI:N), the malicious payload is processed directly by the application layer without prior session validation or credential verification.\nUpon successful processing of the crafted payload, the underlying application logic fails to isolate untrusted input or enforces inadequate access controls, allowing the execution of unauthorized administrative operations or arbitrary code within the context of the application server. This post-exploitation state grants the attacker complete control over the Oracle WebCenter Portal instance. The resulting impact spans total compromise of confidentiality (C:H) through unauthorized data access, integrity (I:H) via unauthorized system modifications, and availability (A:H) through potential service disruption or denial of service."
}
CVE-2026-70970: Oracle WebCenter Portal Remote Takeover (CRITICAL Severity, CVSS: 9.8) - Sceawere