External risk intelligence

Oracle WebCenter Portal Runtime Tools Data Corruption and Unauthorized Access Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-60564

Oracle WebCenter Portal is an enterprise web application platform designed to host web portals and internal or external-facing content management sites. It is commonly deployed as a network-accessible web service, making the Runtime Tools component reachable via standard HTTP protocols in many enterprise web-facing deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified within Oracle WebCenter Portal's Runtime Tools, potentially impacting additional Oracle Fusion Middleware products. This flaw can be exploited by an attacker with network access and low privileges, leading to unauthorized access, modification, or deletion of critical data.

  • Access to sensitive data is at risk.
  • Impacts enterprise content management and portal platforms.
  • Confirm relevance and assess exposure to Oracle WebCenter Portal.

Attack Path

How an attacker could exploit the issue

A low-privileged attacker with network access could exploit this vulnerability by reaching the Runtime Tools component of Oracle WebCenter Portal via HTTP. Successful exploitation could lead to unauthorized modification or complete access to critical data within Oracle WebCenter Portal and potentially impact other connected products.

  • Network access required.
  • HTTP protocol used to trigger.
  • Unauthorized data access and modification.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged attacker with network access could exploit this vulnerability when Oracle WebCenter Portal's Runtime Tools are exposed via HTTP. This could lead to unauthorized modifications or complete access to critical data within Oracle WebCenter Portal, and potentially impact other connected products.

  • Critical data or accessible portal data.
  • Via network access to HTTP services.
  • Unauthorized data access or modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle WebCenter Portal's Runtime Tools component is vulnerable, potentially impacting critical data and access. Ownership will likely fall to the platform or application teams responsible for the Oracle Fusion Middleware deployment, with vendor management possibly involved for coordinated remediation. The first practical step is to confirm where Oracle WebCenter Portal exists, assess its exposure and business criticality, identify the accountable owner, and then develop a remediation plan.

  • Platform/Application teams own the issue.
  • Verify WebCenter Portal exposure and criticality.
  • Plan vendor coordination and remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle WebCenter Portal?

It is an enterprise platform within Oracle Fusion Middleware used to build and manage web portals and content-driven websites. It provides tools for users to interact with enterprise data and applications through a unified web interface, acting as a central hub for organizational content and collaboration services.

What does CVE-2026-60564 mean for data security?

This vulnerability allows an attacker to bypass standard security controls within the Runtime Tools component. It acts as a gateway for unauthorized actors to read, alter, or delete sensitive information stored within the portal. Because the flaw can impact connected middleware products, it carries a broad risk to the integrity and confidentiality of your managed data.

How is this vulnerability triggered?

An attacker triggers the flaw by sending crafted HTTP requests to the Runtime Tools component. It does not require administrative rights, only low-level network access to the portal service. The bug is specifically tied to these tools; disabling or restricting network access to the Runtime component prevents the primary attack path.

Is my Oracle WebCenter Portal instance at risk?

Halo Surface Signal indicates this risk is highest if your portal is deployed as a network-accessible web service. If your installation is exposed to the internet or reachable over your internal network via standard HTTP protocols, the component is likely reachable by an attacker. You should evaluate your network perimeter to see if these tools are unnecessarily exposed.

What should I do first to address this?

Start by identifying all servers running the affected versions, 12.2.1.4.0 and 14.1.2.0.0. Once located, determine if these instances are accessible over the network. Engage your application or platform team to review the business criticality of the portal and coordinate with your vendor support channels to track and apply official security updates as they become available.

References