A critical (CVSS 9.9) vulnerability in Oracle WebCenter Portal lets a low-privileged network attacker fully take over the product and impact adjacent systems, addressed in Oracle's July 2026 Critical Patch Update.
What Is It
CVE-2026-60565 is a vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. Oracle describes it as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the product. Successful exploitation can result in a complete takeover of Oracle WebCenter Portal. The issue carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting full confidentiality, integrity, and availability impact.
Why It Matters
The vulnerability is notable for its scope change (S:C): while the flaw resides in Oracle WebCenter Portal, Oracle warns that attacks may significantly impact additional products beyond the vulnerable component. Combined with low attack complexity, network reachability over HTTP, and no user interaction required, this makes for a highly attractive target. An attacker needs only low privileges to achieve a full takeover, so any exposed or loosely restricted WebCenter Portal instance represents serious risk to the broader environment.
What's Vulnerable
Per Oracle, the affected supported versions of Oracle WebCenter Portal are:
- 12.2.1.4.0
- 14.1.2.0.0
The vulnerable component is Runtime Tools within Oracle Fusion Middleware.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Organizations running the affected versions should apply the fixes from that advisory. This CVE was published on 2026-07-21 and, at the time of writing, is in "Received" status in NVD with the CVSS metrics supplied by Oracle. No CISA KEV entry was supplied, so there is no confirmation of active exploitation in the provided source material.