CRITICAL
9.1 CVE-2026-60728 Published 18 Aug 2026
Oracle WebCenter Portal Portlet Services Unauthorized Data Access and DoS Vulnerability
Worried this affects one of your servers?
A vulnerability has been identified in Oracle WebCenter Portal, a product of Oracle Fusion Middleware, in the Portlet Services component. The flaw is an unauthorized data access and denial-of-service vulnerability.
Affected versions are 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP.
Successful attacks can result in:
- Unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data
- Unauthorized ability to cause a hang or frequently repeatable crash (complete denial of service) of Oracle WebCenter Portal
CVSS 3.1 Base Score is 9.1, with Confidentiality and Availability impacts. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Reference: CVE-2026-60728 on NVD
← Back to Security News