Junglewise Threat Intelligence

CVE-2026-60643: Oracle WebCenter Content takeover in Content Server

CVE-2026-60643 · Severity: high · CVSS 8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Content Server component. An attacker with basic user access can exploit this flaw to take full control of the system, provided they can trick another user into performing a specific action. If successful, this could lead to the theft of sensitive corporate data, unauthorized modification of documents, or a total disruption of the document management service.

Technical details

A vulnerability in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows for unauthorized compromise via the HTTP protocol. The flaw is classified as easily exploitable but requires a low-privileged attacker and human interaction from a victim (User Interaction: Required). Successful exploitation grants the attacker full control over the Confidentiality, Integrity, and Availability of the affected system, effectively leading to a complete application takeover. The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60643
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats