A critical, easily exploitable vulnerability in Oracle WebCenter Content lets an unauthenticated attacker take over the system over the network, carrying a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-60435 is a critical vulnerability in the Content Server component of Oracle WebCenter Content, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful exploitation can result in full takeover of Oracle WebCenter Content. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability with no privileges or user interaction required.
Why It Matters
With a base score of 9.8 (CRITICAL) and an exploitability score of 3.9, this is about as severe as vulnerabilities get. No authentication, no user interaction, and low attack complexity mean a network-reachable Content Server can be fully compromised by a remote attacker. A takeover exposes all managed content and the underlying service to confidentiality, integrity, and availability loss. Note: at the time of this writing, the supplied CISA KEV data contains no entry for this CVE, so there is no confirmation of active exploitation.
What's Vulnerable
The affected product is Oracle WebCenter Content (component: Content Server). Per the NVD record and Oracle, the supported versions affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in Oracle's July 2026 CPU advisory. Given the unauthenticated, network-accessible nature of the flaw, patching should be prioritized. No CISA KEV required-action date is present in the supplied data.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60435, https://nvd.nist.gov/vuln/detail/CVE-2026-60435