External risk intelligence

Oracle WebCenter Portal Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-60562

Oracle WebCenter Portal is a web-based application platform typically deployed to provide portal services to users, which commonly results in the application being reachable via HTTP/HTTPS on the network edge or within internal web environments accessible to authorized users.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle WebCenter Portal, part of Oracle Fusion Middleware. This issue, which can be exploited remotely by an attacker with low privileges, could allow for the complete takeover of the Oracle WebCenter Portal and potentially impact other connected products. The high severity indicates significant potential for confidentiality, integrity, and availability compromise.

  • Attackers can gain control of Oracle WebCenter Portal.
  • Critical systems could be fully compromised.
  • Confirm relevance and assess exposure to Oracle WebCenter Portal.

Attack Path

How an attacker could exploit the issue

An attacker could gain access to Oracle WebCenter Portal over the network with limited privileges. Once inside, they can interact with the Runtime Tools component, triggering a vulnerability that allows them to take complete control of the WebCenter Portal. This compromise can also affect other connected products.

  • Network access, low privileges needed.
  • Runtime Tools component.
  • Full takeover of the portal.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a low-privileged attacker to gain complete control over Oracle WebCenter Portal, potentially affecting other connected products. This is possible when the portal is accessible over a network via HTTP.

  • System data and service availability at risk.
  • Network access via HTTP.
  • Takeover of Oracle WebCenter Portal.

Operational Fix

Recommended remediation, mitigation, and detection steps

Oracle WebCenter Portal administrators and application owners are responsible for addressing this critical vulnerability. The immediate first step is to identify all instances of the affected Oracle WebCenter Portal, confirm their network exposure and business criticality, and then engage the appropriate teams for remediation planning based on the assessed risk.

  • Application owners and infrastructure teams.
  • Confirm network exposure and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle WebCenter Portal?

Oracle WebCenter Portal is a comprehensive platform within the Oracle Fusion Middleware suite designed for building enterprise-grade portals and composite applications. It provides the framework for aggregating content, processes, and applications into a unified user interface, often serving as the central hub for employee intranets or customer-facing web services.

What does CVE-2026-60562 mean for security?

This CVE describes a critical vulnerability that grants an attacker unauthorized control over the system. It affects the Runtime Tools component, which handles portal management functions. Because it allows a low-privileged user to achieve a full takeover, it is classified as a high-severity flaw that compromises the entire confidentiality, integrity, and availability of the platform.

How can an attacker trigger this vulnerability?

An attacker needs network access to the target instance via HTTP to interact with the Runtime Tools component. It is important to note that this is not a client-side issue; it does not require a user to click a malicious link or perform a specific action within a browser. Success depends on the ability of an authenticated user with low privileges to reach the vulnerable component directly over the network.

Is my system at risk?

According to Halo Surface Signal, this vulnerability is most relevant to instances deployed where they are reachable via HTTP/HTTPS. While often found on the network edge to serve users, these portals may also exist within internal web environments. If your instance is accessible to users over the network, it should be considered a priority for assessment, regardless of whether it faces the public internet or sits behind an internal firewall.

Do I need to take action if I run this software?

Yes. Since this vulnerability allows for a full takeover of the portal and potential impact on connected systems, you should immediately inventory your environment to locate all affected versions of Oracle WebCenter Portal. Once identified, evaluate the business criticality of those instances and coordinate with your infrastructure and security teams to prioritize and plan the necessary remediation steps.

References