CRITICAL 9.9 CVE-2026-60730 Published 18 Aug 2026

Oracle WebCenter Portal Composer Takeover Vulnerability

Worried this affects one of your servers?

A vulnerability in Oracle WebCenter Portal (component: Composer) allows a low-privileged attacker with network access via HTTP to compromise the portal. Successful attacks can result in takeover of Oracle WebCenter Portal.

Affected versions are 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is easily exploitable and may significantly impact additional products due to a scope change.

  • CVSS 3.1 Base Score: 9.9
  • Impact: High confidentiality, integrity, and availability impacts
  • Attack vector: Network via HTTP
  • Privileges required: Low

Reference: CVE-2026-60730 on NVD

← Back to Security News