Junglewise Threat Intelligence

CVE-2026-60638: Oracle WebCenter Content takeover in Content Server

CVE-2026-60638 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Content Server component. An attacker can exploit this flaw to take full control of the system, potentially leading to the theft of sensitive data or disruption of business operations. For an attack to succeed, a legitimate user must perform a specific action, such as clicking a malicious link.

Technical details

A vulnerability in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows an unauthenticated remote attacker to compromise the application. The flaw is categorized by a CVSS 3.1 score of 8.8, indicating high impacts on confidentiality, integrity, and availability. While the attack vector is network-based (HTTP), successful exploitation requires user interaction (UI:R), suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar client-side attack that leads to administrative takeover. Organizations should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats