Vulnerability in Oracle WebCenter Content Product from Oracle
CVE-2026-60909

7.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60909?

A vulnerability exists in the Oracle WebCenter Content component of Oracle Fusion Middleware, notably in versions 12.2.1.4.0 and 14.1.2.0.0. This issue allows a low-privileged attacker with network access via HTTP to exploit the system. The attack requires human interaction from a third party. Although the vulnerability is specific to Oracle WebCenter Content, it poses a significant threat as successful exploits could lead to unauthorized access to critical information, including data manipulation rights such as insertion, updating, or deletion of content. Organizations utilizing affected versions are urged to implement security measures promptly to thwart potential exploitation.

Affected Version(s)

Oracle WebCenter Content 12.2.1.4.0

Oracle WebCenter Content 14.1.2.0.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.