CVE-2026-61124: High severity Oracle Oracle WebCenter Portal vulnerability
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Oracle WebCenter Portal deployments running supported affected versions 12.2.1.4.0 or 14.1.2.0.0 are exposed if an unauthenticated attacker can reach them over HTTP. No attacker account or prior privileges are required.
What must an attacker do to exploit it?
The attacker needs network access via HTTP and must induce human interaction by someone other than the attacker. The issue is otherwise described as easily exploitable with low attack complexity.
What is the potential impact of a successful attack?
A successful attack can allow unauthorized creation, deletion, or modification of critical data or all data accessible to Oracle WebCenter Portal. It can also cause a partial denial of service affecting the product.