CRITICAL 9.1 CVE-2026-60728 Published 18 Aug 2026

Oracle WebCenter Portal Portlet Services Unauthorized Data Access and DoS Vulnerability

Worried this affects one of your servers?

A vulnerability has been identified in Oracle WebCenter Portal, a product of Oracle Fusion Middleware, in the Portlet Services component. The flaw is an unauthorized data access and denial-of-service vulnerability.

Affected versions are 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP.

Successful attacks can result in:

  • Unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data
  • Unauthorized ability to cause a hang or frequently repeatable crash (complete denial of service) of Oracle WebCenter Portal

CVSS 3.1 Base Score is 9.1, with Confidentiality and Availability impacts. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).

Reference: CVE-2026-60728 on NVD

← Back to Security News