Junglewise Threat Intelligence

CVE-2026-60552: Oracle WebCenter Sites remote compromise and takeover

CVE-2026-60552 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing and delivering digital content and websites, contains a critical security vulnerability. An attacker with low-level user credentials can exploit this flaw over the network to take full control of the system. This could lead to the theft of sensitive data, website defacement, or the disruption of business operations, and may also allow the attacker to impact other connected systems.

Technical details

A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is characterized by a scope change (S:C), meaning a successful exploit can impact components beyond the security scope of WebCenter Sites. It is easily exploitable by a low-privileged attacker with network access via HTTP without requiring user interaction. Successful exploitation can result in a complete takeover of the Oracle WebCenter Sites instance, granting the attacker full control over confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Initial publication of the vulnerability by Oracle and NVD.

References

Related threats