Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Runtime Tools component of Oracle WebCenter Portal allows an attacker with low privileges who can reach the system over HTTP to compromise the portal. The vulnerability is easily exploitable and can give the attacker full control of the portal, potentially affecting other integrated applications. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) indicates a scope change, leading to confidentiality, integrity, and availability impacts beyond the initial target.

Affected Systems

The affected products are Oracle WebCenter Portal from Oracle Corporation, specifically version 12.2.1.4.0 and 14.1.2.0.0. No other versions are listed as vulnerable in the current advisory.

Risk and Exploitability

The CVSS base score of 9.9 indicates a critical severity. The EPSS score falls below 1% and the vulnerability is not listed in CISA’s KEV catalog, yet the high severity score and scope shift suggest it may be of interest to attackers. Exploitation requires only network access to the portal’s HTTP interface and does not require authentication or elevated privileges. A successful exploit can be achieved via a simple HTTP request, allowing the attacker full control of the portal.

Generated by OpenCVE AI on August 4, 2026 at 17:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Oracle WebCenter Portal patch that removes the Runtime Tools flaw.
  • Limit access to the portal’s HTTP interface by restricting trusted networks, firewalls, or VPN connections to reduce exposure.
  • Apply strict access controls and enable audit logging on the portal, addressing the CWE-284 weakness to detect and prevent unauthorized activity.

Generated by OpenCVE AI on August 4, 2026 at 17:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Portal Runtime Tools Vulnerability Allows Low‑Privilege Portal Takeover via HTTP

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Remote WebCenter Portal Takeover via HTTP with Low Privileges
Weaknesses CWE-863

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Remote WebCenter Portal Takeover via HTTP with Low Privileges
Weaknesses CWE-284
CWE-863

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:28.404Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60562

cve-icon Vulnrichment

Updated: 2026-07-27T12:09:32.595Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses