CVE-2026-60557: Infoleak
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60557?
CVE-2026-60557 has a medium severity score of 6.5.
How do I fix CVE-2026-60557?
To fix CVE-2026-60557, update to a supported version of Oracle WebCenter Sites that is not affected by this vulnerability.
Which versions of Oracle WebCenter Sites are vulnerable to CVE-2026-60557?
The affected versions are 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Sites.
What type of attack can exploit CVE-2026-60557?
CVE-2026-60557 can be exploited by an unauthenticated attacker with network access via HTTP.
What does CVE-2026-60557 mean for data confidentiality?
CVE-2026-60557 poses a risk to data confidentiality as it is classified under infoleak vulnerabilities.