SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60649 2026-07-21

Oracle WebCenter Content Critical Flaw: CVE-2026-60649

"A critical, unauthenticated vulnerability in Oracle WebCenter Content (CVSS 9.1) lets a remote attacker over HTTP read, alter, or destroy any data the product can access."

A critical, unauthenticated vulnerability in Oracle WebCenter Content (CVSS 9.1) lets a remote attacker over HTTP read, alter, or destroy any data the product can access.

What Is It

CVE-2026-60649 is a vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware, specifically in the Web Content Management component. Oracle rates it as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, giving a Base Score of 9.1 (CRITICAL) with the maximum exploitability sub-score of 3.9. No privileges and no user interaction are required.

Why It Matters

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, up to all data accessible to Oracle WebCenter Content, as well as unauthorized read access to that same data. In practical terms, the flaw threatens both the confidentiality and integrity of every asset the platform manages (both are rated High; availability impact is None). Because the attack requires no authentication and only network reachability over HTTP, any internet- or network-exposed instance is at direct risk from low-effort attacks.

What's Vulnerable

The affected product is Oracle WebCenter Content (vendor: Oracle Corporation), part of Oracle Fusion Middleware. The supported versions listed as affected are:

Patch Status

The vulnerability is documented in Oracle's Critical Patch Update for July 2026. Organizations running the affected versions should consult and apply the fixes referenced in the Oracle Critical Patch Update Advisory (cpujul2026). This CVE does not appear in the supplied CISA KEV data, so there is no confirmed record of active exploitation in the source material provided.

Sources