Executive brief
Oracle WebCenter Portal, a platform used by organizations to build and manage intranets and composite applications, contains a critical security vulnerability in its Runtime Tools component. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the portal. This could lead to the theft of sensitive corporate data, disruption of internal business operations, and potential unauthorized access to other connected systems.
Technical details
This vulnerability exists in the Runtime Tools component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The flaw allows for a scope change (S:C), meaning a successful exploit can impact security beyond the WebCenter Portal itself, potentially leading to a complete takeover of the host environment. The vulnerability results in high impacts to confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60561 by Oracle and NVD.