CVE-2026-60568

Oracle · WebCenter Portal

A critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows a low privileged attacker to achieve full system takeover via network-accessible HTTP requests.

Executive summary

A critical vulnerability in Oracle WebCenter Portal permits unauthorized remote takeover of the application, posing an extreme risk to enterprise data and system integrity.

Vulnerability

This is an easily exploitable vulnerability in the Runtime Tools component that allows an authenticated attacker with low privileges to compromise the application via network access. The vulnerability supports scope change, meaning an attacker can potentially impact additional products beyond the portal itself.

Business impact

With a CVSS base score of 9.9, this vulnerability represents a critical threat to business operations. Successful exploitation results in complete system takeover, granting an attacker full control over the portal and potentially adjacent systems, which could lead to massive data exfiltration, unauthorized administrative actions, and significant service disruption.

Remediation

Immediate Action: Apply the relevant patches provided in the July 2026 Oracle Critical Patch Update as soon as they are available.

Proactive Monitoring: Review web server and application logs for suspicious HTTP requests, particularly those originating from low privileged accounts targeting Runtime Tools.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall (WAF) with updated rules to block anomalous traffic patterns targeting Oracle Fusion Middleware components.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity and the potential for total system compromise, administrators must prioritize this update within their standard patching window. Immediate identification of affected instances and the application of vendor-supplied security patches are essential to prevent unauthorized access and maintain the security posture of the Oracle environment.