PT-2026-77479 · Oracle · Oracle Webcenter Portal+1
CVE-2026-61124
·
Published
2026-08-18
·
Updated
2026-08-29
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Oracle WebCenter Portal versions 12.2.1.4.0
Oracle WebCenter Portal version 14.1.2.0.0
Description
An issue in the Runtime Tools component allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation requires human interaction and can lead to the unauthorized creation, deletion, or modification of critical data and all accessible data within the portal. Additionally, this may result in a partial denial of service (partial DOS), which is a condition where the system becomes partially unavailable or unresponsive to some users.
Recommendations
Update Oracle WebCenter Portal version 12.2.1.4.0 to the latest patched version.
Update Oracle WebCenter Portal version 14.1.2.0.0 to the latest patched version.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Webcenter Portal
Webcenter Portal