SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60644 2026-07-21

CVE-2026-60644: Critical Unauthenticated Takeover in Oracle WebCenter Content

"A maximum-severity (CVSS 10.0) flaw in Oracle WebCenter Content lets an unauthenticated attacker with network access take over the product over HTTP, with impact extending to other products via a scope change."

A maximum-severity (CVSS 10.0) flaw in Oracle WebCenter Content lets an unauthenticated attacker with network access take over the product over HTTP, with impact extending to other products via a scope change.

What Is It

CVE-2026-60644 is a critical vulnerability in the Web Content Management component of Oracle WebCenter Content, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful exploitation can result in full takeover of Oracle WebCenter Content.

It carries a CVSS 3.1 base score of 10.0 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required, with high confidentiality, integrity, and availability impact.

Why It Matters

The combination of a 10.0 score, no authentication, and low attack complexity makes this an ideal target for opportunistic attackers. Critically, the vulnerability carries a scope change (S:C): while the flaw resides in WebCenter Content, Oracle warns that "attacks may significantly impact additional products." A single compromised WebCenter Content instance can therefore serve as a pivot beyond its own boundary, and full takeover means an attacker can read, alter, or destroy managed content.

What's Vulnerable

The affected product is Oracle WebCenter Content (Oracle Fusion Middleware), component Web Content Management. The supported versions listed as affected are:

Internet-exposed WebCenter Content instances running these versions are at greatest risk given the network, unauthenticated attack path.

Patch Status

The vulnerability was addressed in Oracle's Critical Patch Update of July 2026. Administrators should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes for affected WebCenter Content versions. No CISA KEV entry accompanies this record, so active exploitation is not confirmed in the supplied data.

Sources