Junglewise Threat Intelligence

CVE-2026-60651: Oracle WebCenter Content takeover in Web Content Management

CVE-2026-60651 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle WebCenter Content, a platform used for managing corporate digital assets and documents. An unauthenticated attacker can exploit this flaw over the network to potentially take full control of the system. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, which could lead to the theft of sensitive business data or a total service disruption.

Technical details

A vulnerability in the Web Content Management component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows for a complete system takeover. The flaw is easily exploitable by an unauthenticated attacker via HTTP; however, it requires user interaction from a person other than the attacker (UI:R). The CVSS vector indicates high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H). While the specific CWE is not detailed in the advisory, the requirement for user interaction and the 'network' attack vector often suggest a cross-site request forgery (CSRF) or a similar client-side injection vulnerability that leads to administrative compromise. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats