Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Portal contains a low‑privilege HTTP vulnerability that permits any user with network connectivity to send crafted requests which can create, delete, or modify critical portal data and grant full read access to all portal content. The flaw exploits improper authorization (CWE‑284) and, as the CVE describes, may affect other products with a scope change, compounding the damage beyond the portal itself.

Affected Systems

The affected products are Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0, components of Oracle Fusion Middleware. No other product versions are currently listed as impacted.

Risk and Exploitability

The CVSS base score of 9.6 signals a severe confidentiality and integrity risk. The EPSS score of < 1 % indicates that widespread exploitation is currently unlikely, yet the vulnerability remains actionable. Because the attack can be performed over HTTP with only low privilege, an adversary can exploit it from any network‑connected host. The flaw is not yet cataloged in the CISA KEV, but its ability to alter and read portal data makes it a critical risk for organizations relying on WebCenter Portal.

Generated by OpenCVE AI on August 2, 2026 at 21:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle WebCenter Portal to the latest patched release that addresses CVE-2026-60564
  • Restrict HTTP access to the portal to trusted IP ranges or enforce VPN tunnels until the patch is applied
  • Ensure users have only the minimum necessary roles so that even if the flaw is exploited, the impact is limited

Generated by OpenCVE AI on August 2, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploitation Leads to Unauthorized Data Modification in Oracle WebCenter Portal

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploitation Leads to Unauthorized Data Modification in Oracle WebCenter Portal

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability in Oracle WebCenter Portal Enabling Unauthorized Data Modification

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability in Oracle WebCenter Portal Enabling Unauthorized Data Modification
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:30.683Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60564

cve-icon Vulnrichment

Updated: 2026-07-27T14:25:24.528Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses