Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a high-severity vulnerability in its Content Server component. An unauthenticated attacker could potentially take full control of the system if a legitimate user interacts with a malicious link or request. This could lead to the theft of sensitive corporate data, unauthorized modification of documents, or a complete disruption of the content management service.
Technical details
This vulnerability exists in the Content Server component of Oracle WebCenter Content (Oracle Fusion Middleware). It is an unauthenticated, network-based attack vector via HTTP. The vulnerability is classified with a high attack complexity (AC:H) and requires user interaction (UI:R), suggesting a possible Cross-Site Scripting (XSS) or Request Forgery (CSRF) variant that leads to full system compromise. A successful exploit results in a scope change (S:C), indicating the attacker may gain unauthorized access to resources beyond the WebCenter Content environment. Impact includes complete loss of confidentiality, integrity, and availability. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-60640 was publicly disclosed.