SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60551 2026-07-21

CVE-2026-60551: Critical Unauthenticated Takeover Flaw in Oracle WebCenter Sites

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60551, a CVSS 9.8 vulnerability in Oracle WebCenter Sites that lets an unauthenticated attacker fully take over the product over the network."

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60551, a CVSS 9.8 vulnerability in Oracle WebCenter Sites that lets an unauthenticated attacker fully take over the product over the network.

What Is It

CVE-2026-60551 is a critical vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Oracle describes it as an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks can result in complete takeover of the product. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of network attack vector, low complexity, no required privileges, and no user interaction makes this among the most severe classes of vulnerability. Because exploitation requires no authentication and only HTTP access, any exposed WebCenter Sites instance is reachable by an anonymous attacker. A successful attack yields full takeover, giving an adversary control over the affected application and its data.

What's Vulnerable

Per Oracle, the affected supported versions are:

Patch Status

This vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026. Administrators should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes for their affected WebCenter Sites versions. No CISA KEV entry accompanying this record was supplied, so active exploitation is not confirmed by the source material provided here.

Sources