CVE-2026-60562

Oracle · WebCenter Portal

A critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows a low privileged, network-based attacker to achieve full system takeover via HTTP.

Executive summary

A critical vulnerability in Oracle WebCenter Portal permits unauthorized system takeover by low privileged attackers, representing a severe risk to organizational infrastructure.

Vulnerability

This vulnerability affects the Runtime Tools component and allows a low privileged, authenticated attacker with network access to execute unauthorized actions, resulting in a full system takeover. The scope of the impact extends beyond the portal itself, potentially affecting other integrated products.

Business impact

Successful exploitation leads to a complete compromise of the Oracle WebCenter Portal, granting attackers full control over the application. Given the CVSS score of 9.9, this vulnerability poses an extreme risk to data confidentiality, integrity, and availability, potentially leading to unauthorized data exfiltration and the compromise of connected systems within the Fusion Middleware environment.

Remediation

Immediate Action: Review the Oracle Critical Patch Update advisory for July 2026 to identify and apply the specific security patches required for your deployment.

Proactive Monitoring: Audit application access logs for unusual activity originating from low privileged accounts and monitor for unexpected changes to system configuration or database entries.

Compensating Controls: Deploy Web Application Firewall rules to detect and block suspicious HTTP requests targeting the Runtime Tools component while preparing for the patch installation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for full system takeover, organizations must prioritize the application of vendor-supplied patches. Administrators should verify their current version of Oracle WebCenter Portal and apply the necessary updates immediately to mitigate the risk of unauthorized access.