Oracle's July 2026 Critical Patch Update discloses CVE-2026-60632, a critical (CVSS 9.3) vulnerability in Oracle WebCenter Content that lets an unauthenticated, network-based attacker compromise the product and impact systems beyond it.
What Is It
CVE-2026-60632 is a vulnerability in the Content Server component of Oracle WebCenter Content, part of Oracle Fusion Middleware. It is easily exploitable by an unauthenticated attacker with network access over HTTP. Successful exploitation requires human interaction from a person other than the attacker. Because the flaw carries a scope change, attacks originating in WebCenter Content may significantly impact additional products beyond the vulnerable component itself.
Why It Matters
The vulnerability holds a CVSS 3.1 base score of 9.3 (CRITICAL), with the vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, up to all WebCenter Content accessible data, as well as unauthorized read access to critical or complete accessible data. Both confidentiality and integrity impacts are rated HIGH; availability is not impacted. The combination of no required privileges, low attack complexity, and cross-product scope change makes this a high-priority patch.
What's Vulnerable
The affected product is Oracle WebCenter Content (component: Content Server), a component of Oracle Fusion Middleware. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators should apply the fixes referenced in the Oracle Critical Patch Update advisory. The NVD record does not indicate CISA KEV listing or confirmed active exploitation at time of publication.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60632, https://nvd.nist.gov/vuln/detail/CVE-2026-60632