Junglewise Threat Intelligence

CVE-2026-60656: Oracle WebCenter Content takeover in Web Content Management

CVE-2026-60656 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a high-severity vulnerability. An attacker with basic user credentials can exploit this flaw over the network to take full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of the content management service.

Technical details

A vulnerability exists in the Web Content Management component of Oracle WebCenter Content (part of Oracle Fusion Middleware). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific CWE is not detailed in the advisory, the impact is rated as high for confidentiality, integrity, and availability, potentially leading to a complete takeover of the affected instance. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats