CRITICAL
9.8 CVE-2026-70970 Published 18 Aug 2026
Oracle WebCenter Portal Runtime Tools Unauthenticated Takeover Vulnerability
Worried this affects one of your servers?
A vulnerability in Oracle WebCenter Portal (Oracle Fusion Middleware, component: Runtime Tools) has been disclosed as an unauthenticated takeover vulnerability. Supported affected versions are 12.2.1.4.0 and 14.1.2.0.0.
This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks can result in takeover of Oracle WebCenter Portal.
- Affected versions: 12.2.1.4.0 and 14.1.2.0.0
- Attack vector: network via HTTP, no authentication required
- CVSS 3.1 Base Score: 9.8 (Confidentiality, Integrity, Availability impacts)
- CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Reference: CVE-2026-70970 on NVD
← Back to Security News