Junglewise Threat Intelligence

CVE-2026-60551: Oracle WebCenter Sites remote compromise vulnerability

CVE-2026-60551 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing large-scale web content and customer experiences, contains a critical security vulnerability. An unauthorized attacker can remotely take full control of the system over the internet without needing any login credentials. This could lead to a total loss of data confidentiality, unauthorized modification of website content, and complete service disruption.

Technical details

A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. While the specific CWE is not detailed in the advisory, the CVSS vector indicates a complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) without requiring user interaction or privileges. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Organizations should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats