Junglewise Threat Intelligence

CVE-2026-60641: Oracle WebCenter Content security bypass in Content Server

CVE-2026-60641 · Severity: high · CVSS 7.6 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform for managing corporate documents and digital assets, contains a vulnerability in its Content Server component. An unauthenticated attacker can exploit this flaw by tricking a legitimate user into performing an action, such as clicking a malicious link. Successful exploitation could allow the attacker to steal sensitive business data, modify or delete records, and cause a partial disruption of the service.

Technical details

This vulnerability affects the Content Server component of Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The attack requires human interaction (UI:R) from a person other than the attacker, suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar client-side injection. Successful exploitation grants the attacker unauthorized read access to critical data, the ability to perform unauthorized updates or deletions of some data, and the capability to cause a partial denial of service. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats