Junglewise Threat Intelligence

CVE-2026-60435: Oracle WebCenter Content remote compromise in Content Server

CVE-2026-60435 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a critical security flaw in its Content Server component. An unauthorized person can remotely take full control of the system over the internet without needing a username or password. This could lead to the theft of sensitive corporate data, total service disruption, or the modification of official records.

Technical details

A critical vulnerability exists in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is categorized as easily exploitable and requires no authentication or user interaction. An attacker can exploit this vulnerability over the network via HTTP to achieve a full compromise of the application. While the specific CWE is not detailed in the advisory, the CVSS score of 9.8 and the 'takeover' description suggest a high-impact flaw such as remote code execution or a complete authentication bypass. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats