Summary
CVE-2026-61193 is a high-severity vulnerability in the Runtime Tools component of Oracle WebCenter Portal (part of Oracle Fusion Middleware), allowing an unauthenticated, remote attacker to compromise the application over HTTP. Oracle classifies it as difficult to exploit, but a successful attack can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all data accessible to Oracle WebCenter Portal. The vulnerability carries a CVSS v3.1 base score of 8.7 and was disclosed by Oracle on August 18, 2026 as part of its Critical Security Patch Update.
Technical details
- Root cause: A flaw in the Runtime Tools component of Oracle WebCenter Portal that permits unauthorized manipulation of application data without authentication.
- Trigger conditions: Oracle describes exploitation as "difficult," indicating the attack requires specific, non-trivial conditions to be met (reflected in a CVSS Attack Complexity rating of High), but no privileges or user interaction are required.
- Attack vector: Network-based, delivered over HTTP against the exposed WebCenter Portal application.
- Impact: A successful attack results in a scope change — meaning the compromise can extend beyond the vulnerable component to affect other products/data. Confirmed impacts include unauthorized creation, deletion, or modification of critical or all accessible data, and unauthorized read access to critical or all accessible data. There is no impact to availability.
Affected software
- Oracle WebCenter Portal 12.2.1.4.0
- Oracle WebCenter Portal 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.7 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the fixes provided by Oracle in the August 2026 Critical Security Patch Update (cspuaug2026) for the affected WebCenter Portal releases (12.2.1.4.0 and 14.1.2.0.0). Oracle strongly recommends applying the update promptly, as it does with all Critical Patch/Security Patch Updates.
- If immediate patching is not possible: Restrict and monitor network/HTTP access to WebCenter Portal instances (e.g., limit exposure to trusted networks, place behind authenticated reverse proxies or WAF rules) until the vendor patch can be applied, and review application logs for anomalous unauthenticated data-modification requests.

