SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60561 2026-07-21

CVE-2026-60561: Critical Scope-Changing Takeover Flaw in Oracle WebCenter Portal

"A low-privileged, network-exploitable vulnerability in Oracle WebCenter Portal carries a near-maximum CVSS score of 9.9 and can lead to full product takeover along with impact to other products."

A low-privileged, network-exploitable vulnerability in Oracle WebCenter Portal carries a near-maximum CVSS score of 9.9 and can lead to full product takeover along with impact to other products.

What Is It

CVE-2026-60561 is a critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. According to Oracle, the flaw is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful exploitation can result in complete takeover of the product. The issue carries a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

Why It Matters

The vulnerability combines several factors that make it especially dangerous: network attack vector, low attack complexity, no user interaction, and only low privileges required. Critically, it involves a scope change (S:C), while the flaw resides in Oracle WebCenter Portal, Oracle notes that attacks "may significantly impact additional products." All three impact dimensions, confidentiality, integrity, and availability, are rated HIGH, reflecting the potential for a complete compromise that extends beyond the vulnerable component itself.

What's Vulnerable

The affected product is Oracle WebCenter Portal (component: Runtime Tools) within Oracle Fusion Middleware. Per Oracle, the supported versions affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should consult the Oracle Critical Patch Update advisory and apply the relevant fixes. The supplied source material does not include a CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the data provided.

Sources