Junglewise Threat Intelligence

CVE-2026-60633: Oracle WebCenter Content remote compromise in Content Server

CVE-2026-60633 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a high-severity vulnerability in its Content Server component. An unauthenticated attacker can exploit this over the network to gain full control of the system, provided they can trick a legitimate user into performing a specific action. A successful attack could lead to the theft of sensitive business data, unauthorized modification of records, or a total service outage.

Technical details

A vulnerability in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows for remote compromise. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP, though it requires user interaction (UI:R) from a person other than the attacker, suggesting a Cross-Site Request Forgery (CSRF) or Cross-Site Scripting (XSS) vector that leads to administrative action. Successful exploitation grants the attacker full control over Confidentiality, Integrity, and Availability (C:H/I:H/A:H), effectively resulting in a complete system takeover. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 CPU.

References

Related threats