CVE-2026-60565
Oracle · WebCenter Portal
A critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows a low privileged, network-based attacker to achieve full system takeover via HTTP.
Executive summary
A critical vulnerability in Oracle WebCenter Portal permits unauthorized system takeover by low privileged attackers, representing a severe risk to organizational infrastructure.
Vulnerability
This vulnerability affects the Runtime Tools component and allows a low privileged, authenticated attacker with network access to execute unauthorized actions, resulting in a full system takeover. The scope of the impact extends beyond the portal itself, potentially affecting other integrated products.
Business impact
Successful exploitation leads to a complete compromise of the Oracle WebCenter Portal, granting attackers full control over the application. Given the CVSS score of 9.9, this vulnerability poses an extreme risk to data confidentiality, integrity, and availability, potentially leading to unauthorized data exfiltration and the compromise of connected systems within the Fusion Middleware environment.
Remediation
Immediate Action: Review the Oracle Critical Patch Update advisory for July 2026 to identify and apply the specific security patches required for your deployment.
Proactive Monitoring: Audit application access logs for unusual activity originating from low privileged accounts and monitor for unexpected changes to system configuration or database entries.
Compensating Controls: Deploy Web Application Firewall rules to detect and block suspicious HTTP requests targeting the Runtime Tools component while preparing for the patch installation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for full system takeover, organizations must prioritize the application of vendor-supplied patches. Administrators should verify their current version of Oracle WebCenter Portal and apply the necessary updates immediately to mitigate the risk of unauthorized access.