Oracle's July 2026 Critical Patch Update discloses CVE-2026-60562, a critical, easily exploitable flaw in Oracle WebCenter Portal that can lead to full product takeover.
What Is It
CVE-2026-60562 is a critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the product. Because the vulnerability carries a scope change, successful attacks may significantly impact additional products beyond WebCenter Portal itself. A successful attack can result in complete takeover of Oracle WebCenter Portal.
Why It Matters
The vulnerability holds a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. That combination, network attack vector, low attack complexity, only low privileges required, and no user interaction, makes it attractive to attackers. Impacts are HIGH across confidentiality, integrity, and availability, and the changed scope means a compromise can cascade to other connected products. The one prerequisite is that the attacker must already hold low-level privileges.
Note: No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.
What's Vulnerable
The affected product is Oracle WebCenter Portal. Per the NVD record, the impacted supported versions are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
This CVE was published as part of the Oracle Critical Patch Update for July 2026. Organizations running the affected versions should consult Oracle's Critical Patch Update advisory and apply the corresponding fixes. No separate required-action deadline was provided in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory, July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60562, https://nvd.nist.gov/vuln/detail/CVE-2026-60562