Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An access‑control flaw in Oracle WebCenter Portal’s Runtime Tools permits an attacker who already has limited access over HTTP to elevate privileges and ultimately gain full control of the portal. The vulnerability does not require authentication or high privileges, and its exploitation would compromise the confidentiality, integrity and availability of the entire portal environment, enabling attacker‑controlled changes, data exfiltration or service disruption.

Affected Systems

Oracle Corporation’s WebCenter Portal component within Oracle Fusion Middleware, specifically the Runtime Tools. Supported affected releases include 12.2.1.4.0 and 14.1.2.0.0. Any installation of these versions exposed to HTTP traffic from untrusted networks is vulnerable.

Risk and Exploitability

The CVSS base score of 8.8 reflects a high severity risk that attackers can achieve compromise from a network accessible point with low attack complexity and low privileges. The EPSS score of less than 1 % suggests the current likelihood of exploitation is low, but the flaw remains critical for environments that allow public or loosely secured portal access. The vulnerability is not listed in the CISA KEV catalog, yet its potential impact warrants immediate attention. An attacker can exploit the flaw remotely over HTTP without needing prior authentication, making the risk significant for exposed portals.

Generated by OpenCVE AI on August 4, 2026 at 17:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch or update released by Oracle for WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0
  • Restrict HTTP access to the portal by whitelisting trusted IP addresses, applying firewall rules or network segmentation until the patch can be applied
  • Review and tighten role‑based access controls within the portal to ensure non‑privileged users cannot perform privileged operations, mitigating the impact of any residual privilege escalation pathways

Generated by OpenCVE AI on August 4, 2026 at 17:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Access Control Failure Allowing Remote Takeover of Oracle WebCenter Portal

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Access Control Failure Allowing Remote Takeover of Oracle WebCenter Portal

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Allows Full Portal Takeover in Oracle WebCenter Portal
Weaknesses CWE-269

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Allows Full Portal Takeover in Oracle WebCenter Portal
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:29.497Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60563

cve-icon Vulnrichment

Updated: 2026-07-27T14:23:27.747Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses