A critical (CVSS 9.9) vulnerability in Oracle WebCenter Sites lets a low-privileged network attacker fully take over the product and pivot into adjacent systems via a scope change.
What Is It
CVE-2026-60552 is a critical vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware. According to Oracle's advisory, it is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks can result in complete takeover of the product. The flaw carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
Why It Matters
The vulnerability combines network attack vector, low attack complexity, and no user interaction, requiring only low privileges to exploit. Critically, the CVSS vector indicates a scope change (S:C): while the flaw resides in WebCenter Sites, Oracle notes that attacks "may significantly impact additional products." The impact is total, high confidentiality, integrity, and availability loss, meaning a successful attacker can read, alter, and destroy data as well as seize control of the application.
What's Vulnerable
Per Oracle and the NVD record, the affected supported versions of Oracle WebCenter Sites are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
The vulnerability was published as part of Oracle's Critical Patch Update for July 2026. Organizations running the affected versions should consult the referenced Oracle Critical Patch Update advisory and apply the corresponding fixes. No CISA KEV entry accompanying this record was supplied, so active exploitation is not confirmed in the source material at time of writing.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60552, https://nvd.nist.gov/vuln/detail/CVE-2026-60552