SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60631 2026-07-21

CVE-2026-60631: Critical Unauthenticated Flaw in Oracle WebCenter Content

"A critical, easily exploitable vulnerability in Oracle WebCenter Content lets unauthenticated network attackers compromise the product and, through a scope change, impact additional systems."

A critical, easily exploitable vulnerability in Oracle WebCenter Content lets unauthenticated network attackers compromise the product and, through a scope change, impact additional systems.

What Is It

CVE-2026-60631 is a critical vulnerability in the Content Server component of Oracle WebCenter Content, part of Oracle Fusion Middleware. It carries a CVSS 3.1 base score of 9.3 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N. The flaw is easily exploitable: an unauthenticated attacker with network access over HTTP can compromise the product. Successful attacks require human interaction from a person other than the attacker.

Why It Matters

Although the vulnerability resides in Oracle WebCenter Content, a scope change means attacks may significantly impact additional products beyond the vulnerable component. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, or all WebCenter Content accessible data, as well as unauthorized access to critical data, up to complete access to all WebCenter Content accessible data. The combination of network reachability, no required privileges, and high confidentiality and integrity impact makes this a high-priority concern for exposed deployments.

What's Vulnerable

The affected product is Oracle WebCenter Content (component: Content Server) from Oracle Corporation. The supported versions affected are:

Patch Status

Oracle addressed this vulnerability in its Critical Patch Update advisory for July 2026. Administrators of affected WebCenter Content deployments should consult the Oracle Critical Patch Update advisory and apply the associated fixes. No CISA KEV entry confirming active exploitation was supplied for this CVE.

Sources