Junglewise Threat Intelligence

CVE-2026-60634: Oracle WebCenter Content compromise in Content Server

CVE-2026-60634 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a high-severity security flaw in its Content Server component. An attacker can exploit this vulnerability over the network to take full control of the system, though the attack requires a legitimate user to perform a specific action, such as clicking a malicious link. Successful exploitation could lead to the theft of sensitive corporate data, unauthorized modification of documents, or a total disruption of the content management service.

Technical details

A vulnerability in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows for a full system takeover. The vulnerability is classified as easily exploitable and is accessible via the HTTP network protocol. While it does not require administrative privileges (PR:N), it does require user interaction (UI:R), suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar client-side attack vector that can be leveraged to execute administrative actions. Successful exploitation results in high impacts to confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References

Related threats