CVE-2026-60552
Oracle · WebCenter Sites
A critical vulnerability in Oracle WebCenter Sites allows low privileged attackers to compromise the system via HTTP.
Executive summary
A critical, remotely exploitable vulnerability in Oracle WebCenter Sites permits full system takeover by authenticated attackers.
Vulnerability
This vulnerability exists in the WebCenter Sites component and is easily exploitable by an attacker with low-level privileges over HTTP. The issue involves a scope change, meaning that an attacker successful in compromising this application could potentially leverage it to compromise other products within the organization.
Business impact
The CVSS score of 9.9 underscores the critical nature of this vulnerability, representing a total compromise of the application. Given that WebCenter Sites often manages public or internal web content, a breach could lead to unauthorized data disclosure, defacement of web properties, or the lateral movement of attackers into more secure network zones.
Remediation
Immediate Action: Apply the required security updates as detailed in the July 2026 Oracle Critical Patch Update.
Proactive Monitoring: Monitor web server logs for irregular HTTP traffic and investigate any unauthorized attempts to access administrative or high-privilege functions.
Compensating Controls: Use a Web Application Firewall to block potentially malicious payloads and ensure that the application is isolated from sensitive internal services via network segmentation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations must move quickly to patch their WebCenter Sites environments. Failure to update the software exposes the organization to severe risk, and patching remains the only reliable method to eliminate this vulnerability.