CRITICAL 9.6 CVE-2026-60905 Published 18 Aug 2026

Oracle WebCenter Content Critical HTTP Vulnerability

Worried this affects one of your servers?

A vulnerability has been found in Oracle WebCenter Content, specifically in the Content Server component of Oracle Fusion Middleware. The issue is an HTTP-based vulnerability that can be exploited by an unauthenticated attacker with network access via HTTP.

Affected versions are 12.2.1.4.0 and 14.1.2.0.0. Successful exploitation requires human interaction from a person other than the attacker, and the impact may extend to additional products (scope change).

  • Unauthorized creation, deletion or modification of critical data or all accessible Oracle WebCenter Content data
  • Unauthorized access to critical data or complete access to all accessible Oracle WebCenter Content data
  • Unauthorized partial denial of service (partial DoS) of Oracle WebCenter Content

The CVSS 3.1 base score is 9.6, with the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L).

Reference: CVE-2026-60905 on NVD

← Back to Security News