SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60552 2026-07-21

CVE-2026-60552: Critical Oracle WebCenter Sites Takeover Flaw

"A critical (CVSS 9.9) vulnerability in Oracle WebCenter Sites lets a low-privileged network attacker fully take over the product and pivot into adjacent systems via a scope change."

A critical (CVSS 9.9) vulnerability in Oracle WebCenter Sites lets a low-privileged network attacker fully take over the product and pivot into adjacent systems via a scope change.

What Is It

CVE-2026-60552 is a critical vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware. According to Oracle's advisory, it is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks can result in complete takeover of the product. The flaw carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

Why It Matters

The vulnerability combines network attack vector, low attack complexity, and no user interaction, requiring only low privileges to exploit. Critically, the CVSS vector indicates a scope change (S:C): while the flaw resides in WebCenter Sites, Oracle notes that attacks "may significantly impact additional products." The impact is total, high confidentiality, integrity, and availability loss, meaning a successful attacker can read, alter, and destroy data as well as seize control of the application.

What's Vulnerable

Per Oracle and the NVD record, the affected supported versions of Oracle WebCenter Sites are:

Patch Status

The vulnerability was published as part of Oracle's Critical Patch Update for July 2026. Organizations running the affected versions should consult the referenced Oracle Critical Patch Update advisory and apply the corresponding fixes. No CISA KEV entry accompanying this record was supplied, so active exploitation is not confirmed in the source material at time of writing.

Sources