Junglewise Threat Intelligence

CVE-2026-60663: Oracle WebCenter Content takeover in Web Content Management

CVE-2026-60663 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a system used for managing corporate documents and digital assets, contains a critical security vulnerability. An attacker with basic user credentials can exploit this flaw over the network to take full control of the system. This could lead to the theft of sensitive business data, unauthorized modification of content, or a complete shutdown of the document management service.

Technical details

A vulnerability in the Web Content Management component of Oracle WebCenter Content (Oracle Fusion Middleware) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is notable for a 'scope change' (S:C), meaning a successful attack can impact security components beyond the immediate Oracle WebCenter Content environment. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.

References

Related threats