Junglewise Threat Intelligence

CVE-2026-60444: Oracle WebCenter Content unauthorized data access in Content Server

CVE-2026-60444 · Severity: high · CVSS 8.5 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a vulnerability that allows an attacker to gain unauthorized access to sensitive data. An individual with low-level user credentials can exploit this flaw over the network to view, modify, or delete critical business information. This could lead to significant data breaches and may also impact other integrated business systems.

Technical details

A vulnerability exists in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation results in a scope change (S:C), meaning the impact can extend beyond the WebCenter Content environment to other integrated products. Attackers can achieve unauthorized read access to all accessible data (Confidentiality: High) and unauthorized update, insert, or delete access to a subset of data (Integrity: Low). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.

References

Related threats