Summary
CVE-2026-60728 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal (part of Oracle Fusion Middleware). The flaw allows an unauthenticated, remote attacker to send a crafted request over HTTP and gain unauthorized access to sensitive data while also being able to trigger a denial-of-service condition. Oracle disclosed the issue as part of its August 2026 Critical Patch Update, and it carries a CVSS v3.1 base score of 9.1 (Critical).
Technical details
- Root cause: An unspecified flaw in the Portlet Services component of Oracle WebCenter Portal that improperly handles attacker-supplied HTTP requests, permitting unauthorized data access and resource exhaustion.
- Trigger conditions: No authentication, privileges, or user interaction are required — the vulnerable component is reachable directly over the network via HTTP.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High confidentiality impact (unauthorized disclosure of sensitive data) and high availability impact (denial of service); no integrity impact reported.
Affected software
- Oracle WebCenter Portal 12.2.1.4.0
- Oracle WebCenter Portal 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Patch Update (Security Alert) for the affected WebCenter Portal releases (12.2.1.4.0 and 14.1.2.0.0). Organizations should patch to the version specified in Oracle’s advisory as soon as possible given the unauthenticated network attack vector and critical severity.
- If immediate patching is not possible: Restrict direct network/internet exposure of Oracle WebCenter Portal Portlet Services endpoints — place the application behind a web application firewall or restrict access to trusted internal networks until the patch can be applied. Monitor WebCenter Portal access logs for anomalous or unauthenticated requests targeting portlet-related endpoints.
- Review Oracle’s official Critical Patch Update advisory for the complete list of impacted components and any additional configuration guidance specific to your deployment.

