External risk intelligence

Oracle WebCenter Portal Runtime Tools Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-60565

Oracle WebCenter Portal is a web-based application platform typically deployed to provide portal services, which are frequently exposed as internet-facing web interfaces or enterprise portals to facilitate user access, making them commonly accessible via network protocols in standard deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Oracle WebCenter Portal, a component within Oracle Fusion Middleware. It could allow an attacker with limited access to gain control of the portal, potentially impacting other connected products. The high severity rating indicates a significant risk to confidentiality, integrity, and availability.

  • A weakness in Oracle WebCenter Portal can be exploited.
  • It could lead to a full takeover of the portal.
  • Confirm relevance and exposure for Oracle WebCenter Portal.

Attack Path

How an attacker could exploit the issue

An attacker could compromise Oracle WebCenter Portal by exploiting a vulnerability accessible over the network. This vulnerability allows a low-privileged user to gain control of the portal, potentially impacting other products.

  • Network access is required.
  • Attacker triggers the Runtime Tools component.
  • Results in full portal takeover.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged attacker with network access could exploit this vulnerability to compromise Oracle WebCenter Portal, potentially leading to the complete takeover of the affected system. This could significantly impact additional products when supported by the advisory.

  • Oracle WebCenter Portal system.
  • Network access via HTTP.
  • Complete takeover of the portal.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Oracle WebCenter Portal impacts Oracle Fusion Middleware and requires immediate attention from teams managing the application and its underlying infrastructure. The first practical step is to inventory all Oracle WebCenter Portal deployments, assess their network exposure and business criticality, and identify the accountable system owner. Planning for remediation should be based on this risk assessment, potentially involving coordination with Oracle or vendor management for patching or configuration changes.

  • Application and infrastructure owners.
  • Confirm network exposure and criticality.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle WebCenter Portal?

Oracle WebCenter Portal is a platform within Oracle Fusion Middleware used to build enterprise portals and web-based applications. It serves as a centralized hub that aggregates content, processes, and applications, allowing users to interact with enterprise information through a single web interface.

What does CVE-2026-60565 mean?

This is a critical security flaw located in the Runtime Tools component of Oracle WebCenter Portal. It represents a serious weakness that allows an attacker with low-level privileges to perform unauthorized actions, ultimately leading to a complete takeover of the portal system.

How is this vulnerability triggered?

An attacker triggers this bug by sending specific HTTP requests to the Runtime Tools component over a network. The vulnerability requires the attacker to have at least low-level access to the portal; it cannot be triggered by someone with no access at all, nor does it rely on physical access to the server.

Is my system at risk?

According to Halo Surface Signal, this software is often deployed as an internet-facing interface to facilitate broad user access. If your Oracle WebCenter Portal instance is reachable over the network, it is at higher risk. You should check if your portal is exposed externally or if it is restricted to internal users.

What should I do first to respond?

Begin by creating a complete inventory of all Oracle WebCenter Portal instances in your environment. Once you have identified these systems, assess their network connectivity and determine who is responsible for each deployment. This will help you prioritize patching and risk mitigation efforts.

References