SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60632 2026-07-21

CVE-2026-60632: Critical Unauthenticated Flaw in Oracle WebCenter Content

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60632, a critical (CVSS 9.3) vulnerability in Oracle WebCenter Content that lets an unauthenticated, network-based attacker compromise the product and impact…"

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60632, a critical (CVSS 9.3) vulnerability in Oracle WebCenter Content that lets an unauthenticated, network-based attacker compromise the product and impact systems beyond it.

What Is It

CVE-2026-60632 is a vulnerability in the Content Server component of Oracle WebCenter Content, part of Oracle Fusion Middleware. It is easily exploitable by an unauthenticated attacker with network access over HTTP. Successful exploitation requires human interaction from a person other than the attacker. Because the flaw carries a scope change, attacks originating in WebCenter Content may significantly impact additional products beyond the vulnerable component itself.

Why It Matters

The vulnerability holds a CVSS 3.1 base score of 9.3 (CRITICAL), with the vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, up to all WebCenter Content accessible data, as well as unauthorized read access to critical or complete accessible data. Both confidentiality and integrity impacts are rated HIGH; availability is not impacted. The combination of no required privileges, low attack complexity, and cross-product scope change makes this a high-priority patch.

What's Vulnerable

The affected product is Oracle WebCenter Content (component: Content Server), a component of Oracle Fusion Middleware. The supported versions listed as affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators should apply the fixes referenced in the Oracle Critical Patch Update advisory. The NVD record does not indicate CISA KEV listing or confirmed active exploitation at time of publication.

Sources