Junglewise Threat Intelligence

CVE-2026-60335: Oracle WebCenter Content compromise in Content Server

CVE-2026-60335 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Content Server component. A high-privileged user can exploit this flaw over the network to gain full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of the content management service.

Technical details

A vulnerability exists in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is categorized as easily exploitable but requires high-privileged credentials to execute. An attacker can leverage network access via HTTP to compromise the system, leading to a complete loss of confidentiality, integrity, and availability (takeover). While the specific CWE is not detailed in the advisory, the impact is described as a full system compromise. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update
  • 2026-07-21: advisory: NVD record published

References

Related threats