A maximum-severity (CVSS 10.0) flaw in Oracle WebCenter Content lets an unauthenticated attacker with network access take over the product over HTTP, with impact extending to other products via a scope change.
What Is It
CVE-2026-60644 is a critical vulnerability in the Web Content Management component of Oracle WebCenter Content, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful exploitation can result in full takeover of Oracle WebCenter Content.
It carries a CVSS 3.1 base score of 10.0 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required, with high confidentiality, integrity, and availability impact.
Why It Matters
The combination of a 10.0 score, no authentication, and low attack complexity makes this an ideal target for opportunistic attackers. Critically, the vulnerability carries a scope change (S:C): while the flaw resides in WebCenter Content, Oracle warns that "attacks may significantly impact additional products." A single compromised WebCenter Content instance can therefore serve as a pivot beyond its own boundary, and full takeover means an attacker can read, alter, or destroy managed content.
What's Vulnerable
The affected product is Oracle WebCenter Content (Oracle Fusion Middleware), component Web Content Management. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Internet-exposed WebCenter Content instances running these versions are at greatest risk given the network, unauthenticated attack path.
Patch Status
The vulnerability was addressed in Oracle's Critical Patch Update of July 2026. Administrators should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes for affected WebCenter Content versions. No CISA KEV entry accompanies this record, so active exploitation is not confirmed in the supplied data.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60644 (source: [email protected])