Junglewise Threat Intelligence

CVE-2026-60655: Oracle WebCenter Content compromise in Web Content Management

CVE-2026-60655 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Web Content Management component. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of the document management service.

Technical details

A vulnerability in the Web Content Management component of Oracle WebCenter Content allows for a complete system takeover. The flaw is reachable via HTTP and requires only low-privileged authentication (PR:L) with no user interaction (UI:N). While the specific CWE is not identified in the advisory, the impact covers a total loss of confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats