Unauthorized Access Vulnerability in Oracle WebCenter Content by Oracle
CVE-2026-60944

8.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60944?

A vulnerability in Oracle WebCenter Content allows an unauthenticated attacker with network access via HTTP to gain unauthorized access to sensitive data. Exploitation of this flaw necessitates human interaction from a third party, heightening the risk of manipulation of accessible data, including unauthorized updates, inserts, or deletions. This vulnerability, present in specific versions of the product, could lead to severe repercussions as it extends beyond Oracle WebCenter Content, potentially affecting other interconnected systems.

Affected Version(s)

Oracle WebCenter Content 12.2.1.4.0

Oracle WebCenter Content 14.1.2.0.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.