CVE-2026-60644
Oracle · Oracle WebCenter Content
A critical vulnerability in the Oracle WebCenter Content Web Content Management component allows unauthenticated attackers to achieve full system takeover via HTTP network requests.
Executive summary
An unauthenticated, remotely exploitable vulnerability in Oracle WebCenter Content poses a critical risk of full system compromise.
Vulnerability
This vulnerability affects the Web Content Management component of Oracle WebCenter Content, enabling an unauthenticated attacker with network access to remotely compromise the system. The attack is carried out over HTTP and is considered easily exploitable.
Business impact
The CVSS score of 10.0 signifies a critical risk, where an attacker can gain complete control over the Oracle WebCenter Content environment. This level of access allows for the total compromise of stored content, potential escalation to other integrated systems, and significant operational disruption.
Remediation
Immediate Action: Users must apply the latest security updates provided in the July 2026 Oracle Critical Patch Update for the affected WebCenter Content versions.
Proactive Monitoring: Monitor access logs for unusual HTTP traffic and establish alerts for unauthorized administrative access attempts or unexpected system configuration changes.
Compensating Controls: Utilize a WAF to inspect and filter incoming HTTP traffic to the WebCenter Content application, blocking any requests that deviate from expected communication patterns.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical severity and potential for total system takeover, immediate remediation is required. Organizations should prioritize patching Oracle WebCenter Content and ensure that all affected instances are updated to the current secure version provided by Oracle.