CVE-2026-60649
A critical flaw in Oracle WebCenter Content allows attackers to create, delete, or modify data without authentication. The vulnerability can be triggered over the network via HTTP and can give an attacker full access to all content stored in the system. It affects Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle WebCenter Content (Oracle Fusion Middleware) versions 12.2.1.4.0 and 14.1.2.0.0, used by organizations that host web content management services.
Real-world impact
An attacker who exploits this flaw can add, remove, or alter critical data, or gain complete access to all content stored in the WebCenter Content system, potentially exposing sensitive information or disrupting business operations.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability is network‑based, requires no authentication, and has high confidentiality and integrity impacts. Because an attacker can fully compromise the data, the score is in the critical range.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- oracle.com/security-alerts/cpujul2026.…vendor advisory