Junglewise Threat Intelligence

CVE-2026-60443: Oracle WebCenter Content unauthorized data access in Content Server

CVE-2026-60443 · Severity: high · CVSS 8.7 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a security vulnerability in its Content Server component. A low-privileged attacker could exploit this flaw to gain unauthorized access to, modify, or delete sensitive business data. Successful exploitation requires a legitimate user to interact with a malicious link or request, and the impact may extend beyond the content management system to other integrated business applications.

Technical details

This vulnerability exists in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as a scope-changing vulnerability (CVSS S:C), likely indicating a Cross-Site Scripting (XSS) or similar injection flaw that allows an attacker to execute actions in the context of another user's session. An attacker requires low-privileged credentials and network connectivity via HTTP. Successful exploitation requires human interaction from a victim. The impact includes high confidentiality and integrity loss, allowing for the unauthorized creation, deletion, or modification of all data accessible to the Content Server.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats