SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61001 2026-08-18

Oracle Web Services Manager Hit With CVSS 9.6 Scope-Changing Flaw

"Oracle disclosed CVE-2026-61001, a critical vulnerability in Oracle Web Services Manager that lets a low-privileged network attacker fully read and modify data, and spill impact into adjacent products."

Oracle disclosed CVE-2026-61001, a critical vulnerability in Oracle Web Services Manager that lets a low-privileged network attacker fully read and modify data, and spill impact into adjacent products.

What Is It

CVE-2026-61001 is a vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware, specifically in the Web Services Security component. Oracle describes it as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise Oracle Web Services Manager.

The CVSS 3.1 base score is 9.6 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N. Attack complexity is low, no user interaction is required, and the scope is changed. Confidentiality and integrity impacts are both HIGH; availability is not affected.

Why It Matters

Successful exploitation results in unauthorized creation, deletion, or modification of critical data, or all data accessible to Oracle Web Services Manager, plus unauthorized access to critical data or complete read access to everything the product can reach.

The scope change is the part worth flagging. Oracle notes that while the vulnerability lives in Oracle Web Services Manager, attacks may significantly impact additional products. A component that brokers web services security sits in a trusted position, so a compromise there does not stay contained to the component itself.

The privileges-required rating is LOW, not NONE, so an attacker needs some existing foothold or account. That is a modest bar in environments where Fusion Middleware credentials are widely provisioned.

There is no CISA KEV entry for CVE-2026-61001 in the supplied data, so active exploitation is not confirmed at this time.

What's Vulnerable

Per Oracle, the affected supported versions of Oracle Web Services Manager are:

Vendor: Oracle Corporation. Component: Web Services Security.

Patch Status

The CVE was published 2026-08-18 and is currently in "Received" status at NVD, meaning the record has not yet completed NVD analysis. The single vendor reference points to Oracle's August 2026 Critical Patch Update advisory, which is where fixed-version and patch details are published. Administrators running the affected versions should review that advisory and apply the corresponding CPU patches. No specific required-action deadline is present in the supplied data.

Sources