Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Content contains a set of weaknesses that allow an unauthenticated attacker with network access via HTTP to compromise the Content Server. The flaw combines improper input validation (CWE‑20), cross‑site request forgery (CWE‑352), open redirect (CWE‑601), and cross‑site scripting (CWE‑79). An attacker must obtain the cooperation of a separate user to confirm a prompt or provide input; after this interaction, the attacker can execute arbitrary code and take full control of the application, compromising confidentiality, integrity, and availability.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected, and the exposed component is the Content Server.

Risk and Exploitability

The CVSS base score is 8.8, indicating high severity. The EPSS score of less than 1% suggests the likelihood of exploitation is currently very low, yet the vulnerability remains exploitable. It is not listed in the CISA KEV catalog, which further implies no known widespread exploitation. However, the requirement of user interaction introduces a social engineering component that could lower the overall barrier of attack. Organizations should treat this as a high‑priority risk even with the low EPSS.

Generated by OpenCVE AI on August 2, 2026 at 21:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Content patch that addresses CVE-2026-60634 as released in the July 2026 security advisory.
  • Restrict HTTP access to the WebCenter Content server so that only trusted internal networks or VPN connections can reach the Content Server component.
  • Monitor web access logs for anomalous requests to the Content Server and audit user interaction patterns to detect attempts to trigger the vulnerability.

Generated by OpenCVE AI on August 2, 2026 at 21:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title HTTP Vulnerability in Oracle WebCenter Content Allows Full Takeover via User Interaction

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Content via HTTP
Weaknesses CWE-284

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-352
CWE-601
CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Content via HTTP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:18.779Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60634

cve-icon Vulnrichment

Updated: 2026-07-27T12:50:31.552Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')