Vulnerability in Oracle WebCenter Content Affects Oracle Fusion Middleware
CVE-2026-60903

8.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60903?

A vulnerability exists in Oracle WebCenter Content within the Oracle Fusion Middleware suite, specifically impacting versions 12.2.1.4.0 and 14.1.2.0.0. This issue allows an unauthenticated attacker with network access via HTTP to exploit the system. Although primarily affecting Oracle WebCenter Content, this vulnerability’s reach extends to potentially compromise additional products. Exploitation could lead to unauthorized creation, deletion, or modification of critical data, and it may also grant sensitive access rights to all data accessible through Oracle WebCenter Content. The implications of such an attack include severe risks to data confidentiality and integrity.

Affected Version(s)

Oracle WebCenter Content 12.2.1.4.0

Oracle WebCenter Content 14.1.2.0.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.