Unauthenticated Remote Code Execution Vulnerability in Oracle WebCenter Content
CVE-2026-60905

9.6CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60905?

An exploitable vulnerability exists in the Oracle WebCenter Content component of Oracle Fusion Middleware. This vulnerability permits unauthorized attackers to gain control over the content stored within the affected versions (12.2.1.4.0 and 14.1.2.0.0) through HTTP requests. The exploitation of this weakness necessitates human interaction, enabling attackers to create, delete, or modify sensitive data and potentially leading to significant impacts on data integrity and availability. Additionally, the threat could affect other associated products and might result in partial denial of service. It is essential for users of Oracle WebCenter Content to apply recommended patches and mitigations to safeguard against these critical risks.

Affected Version(s)

Oracle WebCenter Content 12.2.1.4.0

Oracle WebCenter Content 14.1.2.0.0

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.