Junglewise Threat Intelligence

CVE-2026-60654: Oracle WebCenter Content takeover in Web Content Management

CVE-2026-60654 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Web Content Management component. An attacker with basic user credentials can exploit this flaw over the network to take full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of the content management service.

Technical details

A vulnerability in the Web Content Management component of Oracle WebCenter Content (part of Oracle Fusion Middleware) allows for a complete system takeover. The flaw is categorized as easily exploitable and requires only low-privileged authentication. An attacker can execute the exploit over the network via HTTP without any user interaction. Successful exploitation results in a total loss of confidentiality, integrity, and availability (CVSS 8.8). Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and July 2026 CPU.

References

Related threats