Junglewise Threat Intelligence

CVE-2026-60568: Oracle WebCenter Portal takeover via Runtime Tools

CVE-2026-60568 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle WebCenter Portal. Vendors: Oracle.

Executive brief

Oracle WebCenter Portal, a platform used for building enterprise portals and managing business applications, contains a critical security vulnerability in its Runtime Tools component. A low-privileged user with network access can exploit this flaw to take complete control of the portal. Because this system often integrates with other corporate applications, a successful attack could also compromise additional connected business systems and data.

Technical details

A critical vulnerability exists in the Runtime Tools component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable via the HTTP protocol by a remote attacker with low-level privileges. The vulnerability is characterized by a 'scope change' (CVSS S:C), meaning an exploit can impact resources beyond the immediate security scope of the WebCenter Portal. Successful exploitation allows for a complete takeover of the affected instance, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Portal 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD entry published

References

Related threats