Exploitable Vulnerability in Oracle WebCenter Content by Oracle
CVE-2026-60955

8.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60955?

A security flaw has been identified in Oracle WebCenter Content, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability can be exploited by attackers with high privileges and network access over HTTP, potentially allowing them to create, delete, or modify critical data. Additionally, unauthorized read access to certain data may occur, alongside the possibility of causing a partial denial of service. This vulnerability can have significant ramifications not just for the Oracle WebCenter Content itself but may also impact interconnected systems and solutions.

Affected Version(s)

Oracle WebCenter Content 12.2.1.4.0

Oracle WebCenter Content 14.1.2.0.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.