Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L).
Published: 2026-08-18
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated flaw that allows an attacker with network access via HTTP to create, delete, modify, or access critical data and potentially cause a partial denial of service. The flaw is easily exploitable and requires a human user other than the attacker to interact with the system, such as clicking a malicious link. If exploited, the attacker can alter or steal sensitive information and interrupt service for users. The impact spans confidentiality, integrity, and availability for any data accessible through Oracle WebCenter Content.

Affected Systems

Oracle WebCenter Content, part of Oracle Fusion Middleware, versions 12.2.1.4.0 and 14.1.2.0.0.

Risk and Exploitability

The CVSS base score of 9.6 indicates critical severity. The EPSS score of < 1% implies a very low probability of exploitation in the wild, though not zero. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability over the HTTP interface without credentials, but the need for human interaction (e.g., clicking a link) adds a detection or throttling barrier. The scope change indicates that exploitation may also affect additional Oracle products in the same environment, potentially expanding the impact surface. Overall, the risk remains high and warrants immediate attention.

Generated by OpenCVE AI on August 21, 2026 at 14:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for CVE-2026-60905 as published in the Oracle Security Alert August 2026.
  • Restrict network traffic to the WebCenter Content HTTP endpoints, limiting access to trusted internal networks or using network segmentation.
  • Disable or limit external access to management interfaces, enforce authentication on all remaining web interfaces, and use strong password policies.

Generated by OpenCVE AI on August 21, 2026 at 14:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in Oracle WebCenter Content Allows Data Manipulation and Partial DoS

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T03:55:54.793Z

Reserved: 2026-07-08T15:51:55.601Z

Link: CVE-2026-60905

cve-icon Vulnrichment

Updated: 2026-08-19T12:13:28.374Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:47.003

Modified: 2026-08-27T18:34:23.307

Link: CVE-2026-60905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:30:07Z

Weaknesses