PT-2026-77479 · Oracle · Oracle Webcenter Portal+1

CVE-2026-61124

·

Published

2026-08-18

·

Updated

2026-08-29

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Oracle WebCenter Portal versions 12.2.1.4.0 Oracle WebCenter Portal version 14.1.2.0.0
Description An issue in the Runtime Tools component allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation requires human interaction and can lead to the unauthorized creation, deletion, or modification of critical data and all accessible data within the portal. Additionally, this may result in a partial denial of service (partial DOS), which is a condition where the system becomes partially unavailable or unresponsive to some users.
Recommendations Update Oracle WebCenter Portal version 12.2.1.4.0 to the latest patched version. Update Oracle WebCenter Portal version 14.1.2.0.0 to the latest patched version.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61124

Affected Products

Oracle Webcenter Portal
Webcenter Portal