Junglewise Threat Intelligence

CVE-2026-60664: Oracle WebCenter Content takeover in Content Server

CVE-2026-60664 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a high-severity security flaw. An attacker can exploit this vulnerability over the internet to take full control of the system, though the attack requires a legitimate user to perform a specific action, such as clicking a malicious link. A successful compromise could lead to the theft of sensitive corporate data, loss of service availability, or unauthorized modification of business records.

Technical details

A vulnerability in the Content Server component of Oracle WebCenter Content allows for a complete system takeover. The flaw is categorized as easily exploitable via the HTTP protocol by an unauthenticated remote attacker. While the specific CWE is not provided in the advisory, the requirement for human interaction (UI:R) and the impact on confidentiality, integrity, and availability suggest a high-impact client-side attack vector, such as Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) that leads to administrative session hijacking. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via the July 2026 CPU advisory.
  • 2026-07-21: advisory: NVD published the CVE record.

References

Related threats