Oracle has disclosed a critical, easily exploitable flaw in Oracle WebCenter Portal that lets a low-privileged network attacker take over the product and pivot into other systems.
What Is It
CVE-2026-60568 is a critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows a low-privileged attacker with network access via HTTP to compromise the product. Successful exploitation can result in full takeover of Oracle WebCenter Portal. The vulnerability carries a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
Why It Matters
The near-maximum score reflects a dangerous combination: the attack is remote over HTTP, requires low complexity, needs only low privileges, and demands no user interaction. Critically, the scope is changed (S:C), while the flaw lives in WebCenter Portal, Oracle warns that "attacks may significantly impact additional products," meaning a compromise can extend beyond the portal itself. Impacts to confidentiality, integrity, and availability are all rated HIGH, consistent with a complete takeover scenario.
What's Vulnerable
The affected product is Oracle WebCenter Portal (Oracle Corporation). The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update advisory. Given the CVSS 9.9 rating and low exploitation barrier, patching should be prioritized.
This CVE is not present in the supplied CISA KEV data, so there is no confirmation of active exploitation at this time.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60568: https://nvd.nist.gov/vuln/detail/CVE-2026-60568