CVE-2026-70970
9.8Oracle · WebCenter Portal
A critical vulnerability in the Oracle WebCenter Portal Runtime Tools component allows unauthenticated remote attackers to achieve full system takeover via HTTP.
Executive summary
A critical, unauthenticated remote code execution vulnerability exists in the Oracle WebCenter Portal that enables complete system takeover.
Vulnerability
This vulnerability resides in the Runtime Tools component of the portal, enabling an unauthenticated attacker to exploit the system over HTTP and gain full administrative control.
Business impact
The CVSS score of 9.8 highlights the critical nature of this vulnerability. Successful exploitation permits an attacker to compromise the entire portal environment, leading to significant reputational damage, loss of sensitive corporate data, and potential long-term operational impact.
Remediation
Immediate Action: Update all affected instances of Oracle WebCenter Portal to the patched versions referenced in the August 2026 Oracle Security Alert.
Proactive Monitoring: Monitor for unexpected changes to the portal configuration or unauthorized access attempts within the Runtime Tools interface.
Compensating Controls: Utilize a WAF to block suspicious traffic and restrict public access to the portal management tools until the software can be updated.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical severity and ease of exploitation, administrators must act swiftly to apply vendor patches. Immediate patching is the only effective way to mitigate the risk of full system compromise.