Junglewise Threat Intelligence

CVE-2026-60557: Oracle WebCenter Sites unauthorized data access via HTTP

CVE-2026-60557 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing large-scale web content and digital experiences, contains a security vulnerability that could allow an unauthorized person to access sensitive data. To exploit this, an attacker would need to trick a legitimate user into performing a specific action, such as clicking a malicious link. If successful, the attacker could gain unauthorized access to critical business information or all data managed within the system.

Technical details

A vulnerability in the WebCenter Sites component of Oracle Fusion Middleware allows unauthenticated attackers with network access via HTTP to compromise the system. The flaw is classified as easily exploitable but requires human interaction from a person other than the attacker (UI:R). Successful exploitation results in a high confidentiality impact (C:H), potentially leading to unauthorized access to critical data or complete access to all data within Oracle WebCenter Sites. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. While the specific CWE is not provided, the requirement for user interaction and the network attack vector are consistent with cross-site flaws or similar redirection vulnerabilities.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats