Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Content product of Oracle Fusion Middleware, component Content Server, suffers from an easily exploitable vulnerability (CWE-284). The flaw allows a low‑privileged attacker with network access to the application via HTTP to compromise the installation. Successful exploitation requires human interaction from a user other than the attacker but can result in the attacker gaining unauthorized access to critical data, as well as the ability to insert, update or delete data within the content repository. The CVSS 3.1 base score is 7.6, reflecting high confidentiality impact and low integrity impact.

Affected Systems

Oracle Corporation’s Oracle WebCenter Content, versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability appears in the Content Server component of the Fusion Middleware stack and can affect any deployment of these software releases.

Risk and Exploitability

The CVSS score of 7.6 denotes a high risk for confidentiality loss, while the EPSS for this vulnerability is under 1% indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely over the network via HTTP, with the attacker requiring only a low level of privilege and the cooperation of a user to trigger the payload. Because the flaw can extend its impact to additional products within the same environment, the potential damage may be broader than the initial scope.

Generated by OpenCVE AI on August 4, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the Oracle WebCenter Content patch that addresses CVE-2026-60522, as detailed in Oracle’s CPU July 2026 security advisory.
  • Limit inbound HTTP access to the Content Server to trusted networks or IP ranges, and consider disabling or hardening any remote management functions that are not required.
  • Secure or remove any remote API or administration endpoints to reduce the attack surface.
  • Enable comprehensive logging and real‑time monitoring of the Content Server, and conduct user education on legitimate request handling to mitigate the human‑interaction requirement.

Generated by OpenCVE AI on August 4, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle WebCenter Content

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle WebCenter Content

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Unauthorized Access in Oracle WebCenter Content
Weaknesses CWE-200
CWE-639

Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Unauthorized Access in Oracle WebCenter Content
Weaknesses CWE-200
CWE-639

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:13:49.824Z

Reserved: 2026-07-08T15:51:40.542Z

Link: CVE-2026-60522

cve-icon Vulnrichment

Updated: 2026-07-24T18:13:45.929Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses