Junglewise Threat Intelligence

CVE-2026-60448: Oracle WebCenter Content security bypass in Content Server

CVE-2026-60448 · Severity: high · CVSS 8.7 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a vulnerability in its Content Server component. An unauthenticated attacker could exploit this over the network to gain full access to sensitive business data or modify critical records. This could lead to significant data breaches or the unauthorized deletion of important company information, potentially impacting other integrated business systems.

Technical details

A vulnerability exists in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is reachable via the network over HTTP and does not require authentication, though it is characterized by high attack complexity. Exploitation results in a scope change (S:C), meaning the impact can extend beyond the WebCenter Content environment to other products. Attackers can achieve complete loss of confidentiality and integrity (C:H/I:H) for all data managed by the server. Users should refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats