Unauthenticated Access Vulnerability in Oracle WebCenter Content by Oracle
CVE-2026-60933

7.4HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60933?

An unauthenticated access vulnerability exists in Oracle WebCenter Content, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability allows attackers with network access via HTTP to compromise the system without prior authentication. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, as well as complete access to all data within Oracle WebCenter Content. This presents serious risks to organizations relying on the platform for managing sensitive content.

Affected Version(s)

Oracle WebCenter Content 12.2.1.4.0

Oracle WebCenter Content 14.1.2.0.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.