Junglewise Threat Intelligence

CVE-2026-60646: Oracle WebCenter Content compromise in Web Content Management

CVE-2026-60646 · Severity: high · CVSS 8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a security vulnerability in its Web Content Management component. An attacker with low-level access to the network can trick a legitimate user into performing an action that allows the attacker to take full control of the system. This could lead to the theft of sensitive business documents, unauthorized modification of content, or a complete disruption of the document management service.

Technical details

A vulnerability exists in the Web Content Management component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The attack requires human interaction from a person other than the attacker (User Interaction: Required), suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar UI-based injection. A successful exploit can result in a complete takeover of the Oracle WebCenter Content instance, impacting confidentiality, integrity, and availability. The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Initial publication by Oracle and NVD

References

Related threats