Unauthenticated Remote Code Execution in Oracle WebCenter Content by Oracle
CVE-2026-60664
8.8HIGH
What is CVE-2026-60664?
A vulnerability in Oracle WebCenter Content allows an unauthenticated attacker with network access to exploit the system via HTTP. Exploitation requires human interaction from a user other than the attacker. Successful exploitation can lead to full control over the affected Oracle WebCenter Content installation, resulting in potential confidentiality, integrity, and availability impacts. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected Version(s)
Oracle WebCenter Content 12.2.1.4.0
Oracle WebCenter Content 14.1.2.0.0