Vulnerability in Oracle WebCenter Content Product by Oracle
CVE-2026-60954

8.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60954?

A vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware enables unauthenticated attackers with network access via HTTP to exploit the system. This weakness allows malicious users to potentially create, delete, or modify critical data within Oracle WebCenter Content, affecting the integrity and confidentiality of all accessible data. Although the vulnerability resides within Oracle WebCenter Content, the repercussions could extend to other products, indicating a broader risk. Effective mitigation strategies are imperative to safeguard sensitive information exposed due to this flaw.

Affected Version(s)

Oracle WebCenter Content 12.2.1.4.0

Oracle WebCenter Content 14.1.2.0.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.