Junglewise Threat Intelligence

CVE-2026-60555: Oracle WebCenter Sites remote compromise in WebCenter Sites component

CVE-2026-60555 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing and delivering digital experiences and web content, contains a critical security vulnerability. An unauthorized person can exploit this flaw over the internet without needing any login credentials. A successful attack could allow a complete takeover of the system, potentially leading to the theft of sensitive data, website defacement, or a total service outage.

Technical details

A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware. The flaw is characterized by its low attack complexity and lack of required privileges or user interaction, making it easily exploitable over the network via HTTP. While the specific vulnerability class (e.g., RCE, auth bypass) is not explicitly named in the advisory, the CVSS score of 9.8 and the 'takeover' impact description suggest a complete compromise of confidentiality, integrity, and availability. The issue affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats