Junglewise Threat Intelligence

CVE-2026-60525: Oracle WebCenter Content data compromise in Content Server

CVE-2026-60525 · Severity: high · CVSS 8.2 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a security vulnerability in its Content Server component. A low-privileged user with network access could exploit this flaw to gain unauthorized access to sensitive data or modify critical information. Because the vulnerability allows for a 'scope change,' an attack could potentially impact other integrated business systems beyond the content management platform itself.

Technical details

This vulnerability exists in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as a high-severity issue with a CVSS score of 8.2, primarily due to a scope change (S:C) that allows an attacker to impact products beyond the initial component. The attack vector is network-based via HTTP, requiring low-level privileges (PR:L) and high attack complexity (AC:H). Successful exploitation enables unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible by the WebCenter Content server. The vulnerability was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60525
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats