Junglewise Threat Intelligence

CVE-2026-60554: Oracle WebCenter Sites unauthorized data access vulnerability

CVE-2026-60554 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

A vulnerability in Oracle WebCenter Sites, a platform used for managing and delivering digital content, allows unauthorized individuals to access sensitive information. An attacker can exploit this over the internet without needing any login credentials. This could lead to the exposure of critical business data or a complete breach of all information stored within the system.

Technical details

This vulnerability affects the WebCenter Sites component of Oracle Fusion Middleware. It is characterized by a high confidentiality impact, allowing an unauthenticated attacker to gain unauthorized access to critical data or all data accessible via the platform. The attack vector is network-based (HTTP), requiring no special privileges or user interaction. The root cause is not specified beyond the component level, but the low attack complexity suggests a direct exposure or improper access control. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60554
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats