A low-privileged, network-exploitable vulnerability in Oracle WebCenter Portal carries a near-maximum CVSS score of 9.9 and can lead to full product takeover along with impact to other products.
What Is It
CVE-2026-60561 is a critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. According to Oracle, the flaw is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful exploitation can result in complete takeover of the product. The issue carries a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
Why It Matters
The vulnerability combines several factors that make it especially dangerous: network attack vector, low attack complexity, no user interaction, and only low privileges required. Critically, it involves a scope change (S:C), while the flaw resides in Oracle WebCenter Portal, Oracle notes that attacks "may significantly impact additional products." All three impact dimensions, confidentiality, integrity, and availability, are rated HIGH, reflecting the potential for a complete compromise that extends beyond the vulnerable component itself.
What's Vulnerable
The affected product is Oracle WebCenter Portal (component: Runtime Tools) within Oracle Fusion Middleware. Per Oracle, the supported versions affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should consult the Oracle Critical Patch Update advisory and apply the relevant fixes. The supplied source material does not include a CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the data provided.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60561, https://nvd.nist.gov/vuln/detail/CVE-2026-60561