Vulnerability in Oracle WebCenter Content Causes Data Compromise
CVE-2026-60949

7.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60949?

A vulnerability present in Oracle WebCenter Content within the Oracle Fusion Middleware allows low privileged attackers with network access via HTTP to exploit the system. This exploitation could lead to unauthorized access to sensitive data, granting attackers the ability to execute unauthorized updates, inserts, or deletions of accessible data. Furthermore, while primarily affecting Oracle WebCenter Content, the ramifications of a successful attack could extend to other associated products, thereby amplifying the potential for data compromise and impacting the overall security posture of affected systems.

Affected Version(s)

Oracle WebCenter Content 12.2.1.4.0

Oracle WebCenter Content 14.1.2.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.