Junglewise Threat Intelligence

CVE-2026-60556: Oracle WebCenter Sites unauthorized data access via HTTP

CVE-2026-60556 · Severity: high · CVSS 8.6 · Published 2026-07-21

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing and delivering digital experiences, contains a high-severity vulnerability. An unauthenticated attacker can exploit this over the network to gain unauthorized access to sensitive corporate data. This could lead to a significant breach of confidential information and potentially impact other integrated business systems.

Technical details

A vulnerability in the WebCenter Sites component of Oracle Fusion Middleware allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is characterized by a 'scope change' (S:C), meaning an exploit can impact components beyond the immediate security scope of WebCenter Sites. Successful exploitation results in high confidentiality impacts, allowing unauthorized access to all accessible data within the application. The vulnerability is rated with a CVSS 3.1 base score of 8.6. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Initial advisory published by Oracle and NVD.

References

Related threats