CRITICAL
9.9 CVE-2026-60730 Published 18 Aug 2026
Oracle WebCenter Portal Composer Takeover Vulnerability
Worried this affects one of your servers?
A vulnerability in Oracle WebCenter Portal (component: Composer) allows a low-privileged attacker with network access via HTTP to compromise the portal. Successful attacks can result in takeover of Oracle WebCenter Portal.
Affected versions are 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is easily exploitable and may significantly impact additional products due to a scope change.
- CVSS 3.1 Base Score: 9.9
- Impact: High confidentiality, integrity, and availability impacts
- Attack vector: Network via HTTP
- Privileges required: Low
Reference: CVE-2026-60730 on NVD
← Back to Security News