Junglewise Threat Intelligence

CVE-2026-60550: Oracle WebCenter Sites unauthorized data access via HTTP

CVE-2026-60550 · Severity: high · CVSS 8.6 · Published 2026-07-21

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing and delivering digital experiences and content, contains a high-severity vulnerability. An unauthenticated attacker can exploit this over the network to gain unauthorized access to sensitive corporate data. This could lead to a significant breach of confidential information and potentially impact other integrated business systems.

Technical details

This vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware. It is classified as an unauthenticated, network-based attack vector via HTTP (AV:N/AC:L/PR:N/UI:N). The flaw is characterized by a 'Scope Change' (S:C), meaning a successful exploit can impact resources beyond the security scope of WebCenter Sites itself. The primary impact is a total loss of confidentiality (C:H) for all accessible data within the component. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats